Impact
The vulnerability lies in NVIDIA Megatron Bridge’s handling of untrusted data during deserialization, classified as CWE-502. An attacker could supply crafted input to the bridge, causing the software to interpret the data as executable code or manipulate internal structures, leading to code execution, data tampering, and information disclosure. The impact is high, affecting confidentiality, integrity, and availability wherever the bridge is deployed.
Affected Systems
Vendors and products affected are NVIDIA Megatron Bridge. No version range is specified in the advisory; the vulnerability applies to all currently shipped versions of the bridge until a patched release is deployed.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity risk, and while an EPSS score is not available, the lack of KEV listing suggests no publicly known exploitation yet. Based on the description, the likely attack vector involves remote delivery of malicious serialized data to a bridge component that processes external input; an attacker would need network or protocol access to transmit the payload. The ability to execute arbitrary code means the vulnerability could potentially be leveraged in a broader compromise of the host system or network.
OpenCVE Enrichment