Out-of-Bound Write Vulnerability in NVIDIA DGX Spark GB10
CVE-2025-33190
6.7MEDIUM
What is CVE-2025-33190?
A vulnerability exists in the SROOT firmware of NVIDIA DGX Spark GB10, which could allow an attacker to perform out-of-bound writes. If exploited, this can lead to unauthorized code execution, data integrity issues, service interruptions, or privilege escalation. It is crucial for users and organizations to remain vigilant and apply security measures to mitigate potential risks associated with this vulnerability.
Affected Version(s)
DGX Spark NVIDIA DGX OS All versions prior to OTA0