Impact
NVIDIA Megatron Bridge has a flaw that permits an attacker to cause the system to deserialize untrusted input, potentially leading to remote code execution, data tampering, and information disclosure. The weakness arises from insecure deserialization (CWE-502).
Affected Systems
The affected product is NVIDIA Megatron Bridge. No specific version information is provided; organizations using any currently deployed version should verify compatibility and patch status.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, yet EPSS is not available and the vulnerability is not listed in KEV, suggesting limited public exploitation data. Nonetheless, the ability to deserialize untrusted data typically requires remote or local interaction, making it potentially exploitable in network‑connected environments. The lack of public exploitation may reflect a low current threat, but the high impact warrants precautionary measures.
OpenCVE Enrichment