Impact
The problem is an Improper Input Validation flaw (CWE‑20) that allows an attacker to supply malformed data to the Adobe Content Credentials Command‑Line Tool, JS SDK, or Rust SDK. The bad input causes the targeted component to crash, which results in a denial‑of‑service condition for its users. No data leakage or remote code execution is achievable based on the description provided.
Affected Systems
Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JS SDK, and Adobe Content Credentials Rust SDK are impacted. Version specifics are not listed, so all available releases up to the present should be reviewed for the presence of the flaw.
Risk and Exploitability
The CVSS score of 7.5 signals high severity, while the EPSS score of less than 1% indicates a low likelihood of active exploitation. The vulnerability is not in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote, since the flaw is triggered by malformed input that can be supplied without user interaction, making exposed deployments vulnerable to operational disruption.
OpenCVE Enrichment