Impact
NVIDIA Megatron Bridge contains a flaw that allows untrusted data to be deserialized. If an attacker successfully triggers this path, they can execute arbitrary code, modify data, or disclose sensitive information. The vulnerability is a classic deserialization weakness, identified as CWE-502.
Affected Systems
The affected product is the NVIDIA Megatron Bridge. No specific version information is supplied beyond the product name, so all current releases of this hardware platform are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, as an attacker would need to provide malicious input to the bridge’s data ingestion pathway. Exploitation therefore requires network access to the component and could allow the attacker to compromise the integrity and confidentiality of the bridge’s environment.
OpenCVE Enrichment