Impact
The flaw in NVIDIA Megatron Bridge allows an attacker to cause deserialization of untrusted data, potentially leading to remote code execution, data tampering, and information disclosure. This vulnerability is a classic deserialization vulnerability (CWE-502).
Affected Systems
The affected product is NVIDIA Megatron Bridge; specific version information is not provided in the advisory.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity that could affect the confidentiality, integrity, and availability of systems that rely on the entity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, meaning no confirmed widespread exploitation yet. The likely attack vector involves an attacker supplying untrusted data to the bridge, which, if deserialized without proper validation, can lead to arbitrary code execution.
OpenCVE Enrichment