Impact
The vulnerability in CAI Content Credentials is an integer overflow or wraparound flaw identified as CWE-190. When an attacker supplies an input that causes the integer to wrap, the software can crash, resulting in a denial‑of‑service (DoS) condition. The impact is limited to the application process; the flaw does not enable code execution, privilege escalation, or data disclosure. The description indicates that exploitation does not require user interaction, implying that remote adversaries could trigger the failure if they can reach the vulnerable component. The weakness arises from improper validation or bounds checking of numeric values flowing through the SDK or command‑line tool. Because the flaw only causes a crash, the immediate risk to an attacker is to interrupt service availability, potentially affecting users or downstream services relying on Content Credentials.
Affected Systems
The affected parties are users of Adobe's Content Credentials Command-Line Tool, the JavaScript Software Development Kit (SDK), and the Rust SDK. Specific impacted versions are not disclosed in the current data, so all released releases that include the vulnerable code paths should be considered at risk until an official patch is posted. No vendor‑specified version list is available in the current reference material. Administrators should verify the version of each component in use and refer to Adobe's security advisory for the precise scope once it is released.
Risk and Exploitability
The CVSS score of 6.2 classifies the flaw as a moderate‑severity DoS vulnerability. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild at the time of this analysis. Adobe has not listed this issue in the CISA KEV catalog, further suggesting limited active exploitation. Attackers would need network access to the vulnerable component or the ability to supply crafted input; no user interaction is required. Given the relatively low exploit probability and the moderate severity, the risk is primarily in environments where uptime is critical and the vulnerability is not yet remediated.
OpenCVE Enrichment