Impact
NVIDIA Megatron Bridge is vulnerable to insecure deserialization of untrusted data. The flaw permits an attacker to supply crafted input that, when deserialized by the system, can lead to arbitrary code execution, data tampering, and information disclosure. The resulting impact gives the attacker significant control over the affected device.
Affected Systems
The vulnerability applies to NVIDIA Megatron Bridge. Specific affected versions are not listed in the available documentation, so any installation that has not applied a vendor patch may be at risk.
Risk and Exploitability
The CVSS score is 7.8, indicating a high severity. An exploitable deserialization flaw typically requires an attacker to deliver malicious data—likely through a remote API or interface—though the exact attack vector is not detailed. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that while exploitation is detectable, the known exploitation probability remains uncertain.
OpenCVE Enrichment