Impact
CAI Content Credentials is vulnerable to an uncontrolled resource consumption flaw (CWE-400) that can lead to application denial-of-service. The flaw does not require user interaction, so an attacker can trigger it remotely by sending crafted requests or invoking the command-line tool with malicious input. Based on the description, it is inferred that the attacker can trigger resource exhaustion by sending malformed or high-volume payloads, exhausting CPU or memory resources and rendering the affected applications unavailable.
Affected Systems
Adobe Content Credentials Command-Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK. Any deployment of these components is potentially affected, as version numbers are not disclosed; apply a patch or remove the components.
Risk and Exploitability
The CVSS score of 6.2 classifies the vulnerability as moderate severity. The EPSS score of less than 1% indicates a low likelihood of exploitation, and it is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw by sending malformed input or executing the command-line tool with high-volume payloads, which consumes system resources without requiring the user to interact with the application.
OpenCVE Enrichment