Impact
The flaw in NVIDIA Megatron Bridge for Linux allows deserialization of untrusted data, enabling an attacker to execute arbitrary code. The vulnerability also carries risks of privilege escalation, data tampering and information disclosure, as identified by CWE-502.
Affected Systems
Linux installations of NVIDIA Megatron Bridge are potentially affected. Specific product versions are not listed in the available data, so any deployment of the bridge may be vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity impact. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could send crafted serialized data over a network connection to trigger the vulnerable deserialization routine, leading to the possibility of remote code execution and subsequent privilege escalation.
OpenCVE Enrichment