NVIDIA DGX Spark GB10 Vulnerability in SROOT Firmware
CVE-2025-33200

2.3LOW

Key Information:

Vendor

Nvidia

Status
Vendor
CVE Published:
25 November 2025

What is CVE-2025-33200?

The NVIDIA DGX Spark GB10 contains a resource reuse vulnerability in its SROOT firmware. An attacker exploiting this issue could potentially gain unauthorized access to sensitive information by forcing a resource to be reused. This type of vulnerability raises serious concerns for data integrity and confidentiality, making it crucial for users to apply remediation measures promptly.

Affected Version(s)

DGX Spark NVIDIA DGX OS All versions prior to OTA0

References

CVSS V3.1

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.