Impact
NVIDIA Megatron Bridge contains a flaw that allows an attacker to deserialize untrusted data. If successfully exploited the component could execute arbitrary code, modify data integrity, and expose sensitive information. The weakness is a classic deserialization vulnerability, identified as CWE-22 and CWE-502, where improper validation of input before processing can lead to severe compromise of confidentiality, integrity, and availability.
Affected Systems
The vulnerable product is NVIDIA Megatron Bridge. No specific version information is provided in the advisory, so the issue may affect all releases of the component until an official patch is released.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high severity level; the EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves the attacker supplying crafted data to the deserialization routine, possibly via a network interface or cached input, to trigger the vulnerability. The absence of a low exploit probability metric means the lack of recent exploitation data rather than an indication of low risk. An attacker who can supply the malicious payload can gain code execution privileges, making this a critical risk for systems that rely on Megatron Bridge for secure processing.
OpenCVE Enrichment