Home
HIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
All versions prior to OTA0
affected
Description
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-bound write. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, information disclosure, or escalation of privileges.
Problem types
Product status
All versions prior to OTA0
References
nvd.nist.gov/vuln/detail/CVE-2025-33189
www.cve.org/CVERecord?id=CVE-2025-33189
nvidia.custhelp.com/app/answers/detail/a_id/5720