Impact
The vulnerability is an integer overflow or wraparound in the CAI Content Credentials Command‑Line Tool and Rust SDK. The flaw occurs when processing numeric arguments, allowing a malformed input to overflow internal counters and crash the application, leading to a denial‑of‑service condition. The CVE identifies the weakness as CWE‑190 and the associated CVSS score is 5.5, indicating a moderate potential impact if exploited.
Affected Systems
Vulnerable products include Adobe Content Credentials Command‑Line Tool and Adobe Content Credentials Rust SDK. No specific affected versions are listed in the advisory, so all versions of these tools are potentially impacted until a patch is released. Users should consult the Adobe security advisory linked in the references for the latest version information.
Risk and Exploitability
The exploit requires user interaction: a victim must open a specially crafted URL or visit a compromised web page that feeds malicious data to the tool. EPSS is not available and the vulnerability is not listed in CISA's KEV catalog, so the current probability of exploitation is uncertain. Given the medium CVSS score and the need for user action, the risk is moderate but can still disrupt services if the tool is relied upon for critical workflows.
OpenCVE Enrichment