Impact
NVIDIA Megatron Bridge is vulnerable to deserialization of untrusted data, which can be leveraged to execute arbitrary code, alter data, or expose sensitive information. The flaw allows an attacker to inject malicious payloads that are processed by the bridge during data handling, leading to potential compromise of both confidentiality and integrity of the system.
Affected Systems
The vulnerability affects NVIDIA Megatron Bridge. No specific affected product versions are listed in the available data. Administrators should verify the current firmware or software revision of their devices and consult NVIDIA documentation for potential updates.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, though the EPSS score is not available, suggesting limited publicly available evidence of exploitation. The vulnerability is not listed in CISA KEV, implying it may not yet be widely exploited. Based on the description, it is inferred that the attack vector likely involves remote delivery of malicious data to a component that performs deserialization, potentially through network services exposed by the bridge. Proper access controls and validation are essential to mitigate this risk.
OpenCVE Enrichment