Impact
NVIDIA Megatron Bridge for Linux suffers from a deserialization weakness (CWE-502) that permits the processing of untrusted data. An attacker who can supply such data to the Bridge may achieve arbitrary code execution, elevate privileges, tamper with data, and expose confidential information.
Affected Systems
The vulnerability targets NVIDIA Megatron Bridge for Linux. No specific affected versions are provided in the advisory; therefore all releases may be at risk until the vendor publishes a fix.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of < 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker would need to supply malicious serialized data to the Megatron Bridge service, presumably over a network connection, to trigger the vulnerability and execute code.
OpenCVE Enrichment