Impact
NVIDIA Megatron Bridge is vulnerable when it deserializes data without validating it. An attacker who can supply such data may force the bridge to execute arbitrary code, modify stored information, or disclose sensitive data. The flaw lies in the handling of untrusted serialized payloads.
Affected Systems
Vendor NVIDIA, product Megatron Bridge. The vulnerability applies to all versions of the Megatron Bridge firmware that have not yet incorporated the vendor's fix, according to the advisory. No specific version range is listed in the data, so all current releases should be examined for the presence of the patch.
Risk and Exploitability
The CVSS score of 7.8 classifies this issue as high severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified from the data, but the lack of KEV listing indicates that the vulnerability has not yet been observed in widespread attacks. The most likely attack vector is remote, via any external input that the bridge accepts, although the exact method of triggering the deserialization flaw is not stated and must be inferred from the description.
OpenCVE Enrichment