Impact
An attacker can trigger the deserialization of untrusted data within NVIDIA Megatron Bridge, which may allow code execution, data tampering, and information disclosure. The flaw maps to CWE‑502, representing insecure deserialization.
Affected Systems
The vulnerability affects NVIDIA Megatron Bridge products; no specific version details are disclosed, implying that all releases of the bridge are potentially affected until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity and the lack of EPSS data suggests no public exploitation has been observed yet. The grace to exploit the issue requires an attacker to supply a crafted serialized payload to the bridge, which is typically reachable over a network or through embedded devices. The vulnerability is not listed in the CISA KEV catalog, but its high impact and remote nature warrant immediate attention.
OpenCVE Enrichment