Impact
The NVIDIA Megatron Bridge product contains a deserialization issue where untrusted data can be processed by the system. An attacker who can supply such data may cause the system to execute arbitrary code, modify or leak data. The vulnerability is identified as a binary deserialization flaw (CWE‑502).
Affected Systems
Products affected are NVIDIA Megatron Bridge, as reported by the CNA. No version range is explicitly specified in the advisory, so any deployment of Megatron Bridge that processes external data may be susceptible until a patch is released.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high severity. The EPSS score is not available, but the lack of a CISA KEV listing means there are no confirmed exploitation reports at this time. The attack vector is not explicitly detailed, but the vulnerability requires an attacker to deliver untrusted data to the bridge, likely over a network or through a exposed API, and if successful, the attacker can achieve remote code execution and data tampering.
OpenCVE Enrichment