Impact
The vulnerability lies in CAI Content Credentials, where improper input validation can cause an application crash and result in a denial‑of‑service. Exploitation does not require user interaction, allowing an attacker to trigger the fault simply by supplying crafted input.
Affected Systems
Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JS SDK, and Adobe Content Credentials Rust SDK are affected. The advisory does not list specific version numbers, so all releases may be is applied.
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate severity. The EPSS score, less than 1%, suggests that the likelihood of exploitation at present is low. Based on the description, it is inferred that since no user interaction is required, any actor who can supply crafted input may potentially trigger the crash; therefore both local and remote actors could exploit this vulnerability, although the risk remains moderate and this issue is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment