Impact
An attacker could exploit a deserialization flaw in NVIDIA Megatron Bridge that allows the execution of arbitrary code, tampering of data, and the disclosure of sensitive information. The vulnerability is based on Unsafe Object Deserialization (CWE‑502) and is triggered when the bridge processes untrusted payloads.
Affected Systems
The affected product is NVIDIA Megatron Bridge. No specific version information is provided in the advisory.
Risk and Exploitability
The CVSS score of 7.8 classifies this as high severity. EPSS data is not available, so the likelihood of exploitation is uncertain, but the potential impact is significant. The breach is not currently listed in the CISA KEV catalog, indicating no public exploit evidence yet. The likely attack vector involves an attacker transmitting malicious serialized data to the bridge’s input interface, which could be over a network or interconnect, allowing the compromise of the bridge’s host system.
OpenCVE Enrichment