Impact
The vulnerability is an integer overflow or wraparound flaw (CWE-190) that can cause the Adobe Content Credentials Command-Line Tool, JavaScript SDK, or Rust SDK to crash when numeric inputs exceed their allowed bounds. This leads to a denial‑of‑service condition, allowing an attacker to disrupt application availability without requiring user interaction.
Affected Systems
Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK are affected. No specific version numbers are defined in the advisory, so all currently released versions may be vulnerable until an update includes the fix.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in CISA's KEV catalog. Exploitation does not require user interaction. The attack vector is not explicitly disclosed; it is inferred that any entity capable of supplying inputs to the affected component could trigger the denial‑of‑service, either locally or remotely.
OpenCVE Enrichment