Impact
NVIDIA Megatron Bridge suffers from a deserialization flaw where untrusted data can be processed. An attacker who successfully exploits this vulnerability can execute arbitrary code, tamper with data, and disclose confidential information. The weakness is a classic deserialization of untrusted data issue, aligned with CWE‑502.
Affected Systems
The affected vendor is NVIDIA, specifically the Megatron Bridge product. No precise version information is available from the CVE entry, so any deployment of this component may be susceptible until the vendor releases a fix.
Risk and Exploitability
The CVSS score of 7.8 denotes a high‑severity condition. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw involves processing external input, the likely attack vector is remote, with an attacker sending crafted payloads over the network or through any interface that accepts serialized data. Successful exploitation would give the attacker full control over the affected process, raising the confidentiality, integrity, and availability of the system.
OpenCVE Enrichment