Impact
An integer underflow flaw in Adobe CAI Content Credentials causes an unsigned value to wrap, which triggers a crash path during input handling. The crash leads to a denial‑of‑service condition. The advisory does not state any compromise of confidentiality or integrity, so the impact is limited to availability.
Affected Systems
Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK are affected. Version information is not disclosed in the advisory; therefore any current instance of these components could be vulnerable.
Risk and Exploitability
The CVSS score of 6.2 classifies the issue as moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation. It is not listed in the CISA KEV catalog. Exploitation does not require user interaction; the likely attack surface involves supplying malformed data to the SDK or tool, although explicit details are not provided.
OpenCVE Enrichment