Impact
NVIDIA Megatron Bridge is vulnerable to a deserialization flaw where malicious data can be processed, potentially allowing an attacker to execute arbitrary code, tamper with data, or disclose sensitive information. The weakness stems from insufficient validation of input during deserialization, as indicated by CWE-502. A successful exploitation would compromise the confidentiality, integrity, and availability of systems interacting with the bridge.
Affected Systems
Affected are the NVIDIA Megatron Bridge product. The product identifier is NVIDIA:Megatron Bridge. No specific versions were disclosed, so all releases that include this deserialization logic remain vulnerable until updated.
Risk and Exploitability
The CVSS score of 7.8 points to a high severity vulnerability. No EPSS score is available, so the exact likelihood of exploitation is unknown, but the absence of this metric does not diminish the risk. The vulnerability is not currently listed in the CISA KEV catalog, which suggests no publicly documented exploits yet. Attackers would need to supply crafted data to the bridge, likely over a network interface, to trigger the deserialization path. This inferred attack vector highlights the potential for remote exploitation.
OpenCVE Enrichment