Impact
NVIDIA Megatron Bridge for Linux contains a flaw that permits an attacker to deserialize untrusted data. This weakness, which follows CWE-94, opens the possibility of arbitrary code execution, privilege escalation, data tampering, and information disclosure.
Affected Systems
All installations of NVIDIA Megatron Bridge for Linux are potentially affected, as no specific version information is provided and any instance of this product should be treated as vulnerable until an official fix is released.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high severity, while the EPSS score of < 1% signifies a very low probability of exploitation at present. The vulnerability is not listed in CISA KEV, so it is not known to be actively exploited. The attack vector is not explicitly stated in the description; based on the description, it is inferred that any interface that accepts serialized input and performs unrestricted deserialization could be a potential path for the attacker to execute arbitrary code with the privileges of the Megatron Bridge process.
OpenCVE Enrichment