Impact
NVIDIA Megatron Bridge is affected by a deserialization flaw that allows an attacker to process untrusted data. If the vulnerability is exploited, it may lead to code execution, data tampering, and information disclosure. This weakness is classified as dangerous deserialization (CWE-502).
Affected Systems
The vulnerable component is NVIDIA’s Megatron Bridge. No specific version information is provided in the advisory, so all installations using this product should verify whether they are affected.
Risk and Exploitability
The CVSS score of 7.8 marks this vulnerability as high severity. Although an EPSS score is not available, the lack of a KEV listing does not diminish the potential impact. Based on the description, the likely attack vector is remote, as the flaw involves processing data that an attacker can supply to the bridge. Successful exploitation could compromise confidentiality, integrity, and availability of the target system.
OpenCVE Enrichment