Impact
The vulnerability allows an attacker to trigger a deserialization of untrusted data within the NVIDIA Megatron Bridge. Deserialization of crafted payloads can lead to code execution, data tampering, and information disclosure. This weakness is a classic instance of insecure deserialization (CWE-502).
Affected Systems
The NVIDIA Megatron Bridge hardware component is affected. No specific version information was provided; all released versions are presumed vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. EPSS is not available, so the current exploitation probability is unknown, and the vulnerability is not listed in CISA KEV, suggesting no publicly documented exploits yet. Based on the description, a successful exploit would require an attacker to provide malicious serialized data to the bridge; the exact attack vector (local or remote) is not disclosed, so the exploit path is inferred to involve either local access or remote exposure of the bridge interface, which is not specified.
OpenCVE Enrichment