Impact
NVIDIA Megatron Bridge is vulnerable to the deserialization of untrusted data, which an attacker can trigger to execute arbitrary code, modify data, or exfiltrate information. The flaw arises when the bridge processes input that has not been validated or authenticated, allowing malicious payloads to be reconstructed into executable objects. This can compromise the integrity and confidentiality of the bridge’s environment.
Affected Systems
Affected parties include any systems utilizing NVIDIA Megatron Bridge. No specific firmware or software version details are provided in the advisory, so all deployments of the product should be treated as potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the advisory notes that the EPSS score is not available. The vulnerability is not listed in CISA KEV, but the potential for remote code execution and data tampering makes it a serious risk. The likely attack vector is remote: an adversary supplying crafted data to the bridge, as the flaw centers on deserializing externally supplied input.
OpenCVE Enrichment