Impact
NVIDIA Megatron Bridge contains a flaw that allows an attacker to deserialize untrusted data, which can lead to code execution, data tampering, and information disclosure. This deserialization vulnerability is the root cause behind the potential compromise and is classified under CWE-502, indicating improper handling of deserialized data.
Affected Systems
The affected product is NVIDIA Megatron Bridge. No specific version range is disclosed, so all deployments of this product may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 signals a high severity. Because the EPSS score is unavailable, the exact likelihood of exploitation is unknown, but the vulnerability is not listed in CISA’s KEV catalog. The only known information indicates that the flaw can be triggered through untrusted serialized input, implying a remote attack vector where an adversary sends crafted data to a vulnerable service. An exploitation attempt could elevate privileges or achieve full system compromise, depending on the bridge’s operating permissions.
OpenCVE Enrichment