Vulnerability in NVIDIA DGX Spark GB10 Affecting SoC Security
CVE-2025-33187

9.3CRITICAL

Key Information:

Vendor

Nvidia

Status
Vendor
CVE Published:
25 November 2025

What is CVE-2025-33187?

The NVIDIA DGX Spark GB10 presents a security flaw within the SROOT component, allowing attackers with privileged access the potential to interact with sensitive System on Chip (SoC) areas. An exploit of this nature could facilitate unwarranted code execution, expose confidential information, enable unauthorized data alterations, disrupt service availability, or escalate user privileges unlawfully. Organizations using affected products must assess their security posture and implement appropriate measures to mitigate the associated risks.

Affected Version(s)

DGX Spark NVIDIA DGX OS All versions prior to OTA0

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.