Impact
NVIDIA Megatron Bridge allows an attacker to trigger deserialization of data that is not fully trusted. This flaw can result in code execution, data tampering, and information disclosure. The weakness corresponds to CWE-502, which covers insecure deserialization instances.
Affected Systems
The vulnerability affects all installations of NVIDIA Megatron Bridge. No specific firmware or software version numbers are provided, so all current releases are considered at risk until a vendor update is applied.
Risk and Exploitability
The CVSS base score of 7.8 indicates moderate to high severity, and while an EPSS score is not available, the lack of a KEV listing suggests no publicly known exploits have been observed. The reported issue involves processing untrusted input, indicating a potential remote attack vector, although the exact channel (network, USB, etc.) was not specified in the advisory. Attackers would need to supply crafted data that the bridge accepts for deserialization to trigger the vulnerability. Given the serious nature of code execution and the absence of known mitigations in the public data, immediate attention is warranted.
OpenCVE Enrichment