Impact
Adobe’s CAI Content Credentials contains an Integer Overflow or Wraparound flaw (CWE‑190) that can allow an attacker to crash the application, resulting in a denial‑of‑service condition without requiring any user interaction.
Affected Systems
The vulnerability affects Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JS SDK, and Adobe Content Credentials Rust SDK.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. It is not listed in CISA KEV, so there is no evidence of widespread active exploitation. The likely attack vector is via malformed or crafted input that triggers the integer wraparound; this inference comes from the description stating that exploitation does not require user interaction.
OpenCVE Enrichment