Impact
NVIDIA Megatron Bridge contains a deserialization flaw that allows malicious actors to supply crafted data, causing an untrusted object to be deserialized. Successful exploitation can lead to arbitrary code execution, data tampering, and information disclosure. This represents a serious confidentiality, integrity, and availability threat inherent to deserialization vulnerabilities (CWE‑502).
Affected Systems
The affected product is NVIDIA Megatron Bridge from NVIDIA. No specific version numbers are listed, so all installations of this product could potentially be vulnerable until an official fix is released.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the EPSS score is not available. The vulnerability is not listed in CISA KEV, but deserialization issues are frequently exploited in the wild. Attackers can potentially transmit malicious payloads over the network to trigger the flaw, exploiting the lack of validation of inbound serialized data. The impact includes code execution and data compromise.
OpenCVE Enrichment