Impact
NVIDIA Megatron Bridge is affected by a deserialization flaw that allows untrusted data to be processed by the application. This flaw can lead to code execution, tampering of data, and information disclosure if an attacker supplies malicious input. The vulnerability is categorized as CWE-502.
Affected Systems
The vulnerability applies to NVIDIA Megatron Bridge. Specific version information beyond the product name is not stated in the available data, so all releases of the product are potentially impacted until a vendor hotfix is released.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability presents a high consequence for confidentiality, integrity, and availability. While the EPSS score is missing, the lack of KEV listing indicates no confirmed exploits yet, yet the privacy implication of deserialization makes it a likely target for future attacks. The attack vector is presumed to be remote, targeting components that deserialize external data; attackers could send crafted data over the network to trigger the flaw. The overall risk demands prompt mitigation.
OpenCVE Enrichment