Impact
NVIDIA Megatron Bridge has an unsafe deserialization flaw where untrusted data can be processed without proper validation, potentially allowing an attacker to execute code, tamper with data, or expose sensitive information. The vulnerability relies on CWE‑502, meaning that an attacker can inject malicious payloads that will be instantiated during deserialization.
Affected Systems
The vulnerability affects NVIDIA Megatron Bridge devices. No specific version information is provided for impacted releases, so all current and future builds of the bridge product should be considered potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity of this flaw. EPSS data are not available, so the exact likelihood of exploitation cannot be quantified at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the nature of the flaw, the likely attack vector is a remote or network‑based delivery of crafted data to the bridge—though explicit network access details are not supplied in the advisory.
OpenCVE Enrichment