Impact
NVIDIA Megatron Bridge is vulnerable to deserialization of untrusted data, a condition that can allow an attacker to inject malicious payloads into the system, thereby enabling execution of arbitrary code and compromising integrity, facilitating data tampering, and exposing sensitive information. The vulnerability is categorized as CWE-502, which concerns unsafe deserialization.
Affected Systems
The affected vendor is NVIDIA and the product is Megatron Bridge; specific version information is not disclosed, so any deployment using the current, unpatched Megatron Bridge implementation could be at risk. Administrators must verify their installed firmware or software against NVIDIA's released updates.
Risk and Exploitability
The CVSS score of 7.8 classifies this flaw as High severity, indicating that an exploited vulnerability would have significant consequences. The absence of an EPSS rating and a listing in the CISA KEV catalog suggests exploitation likelihood is currently unknown, yet the potential for remote code execution, data tampering, and information disclosure warrants prompt action. Attackers would need to transmit crafted data to the bridge, likely via exposed network interfaces or local access, to trigger unsafe deserialization.
OpenCVE Enrichment