CVE-2025-33189

7.8

NVIDIA · DGX Spark GB10

NVIDIA DGX Spark GB10 contains an out-of-bounds write vulnerability in the SROOT firmware that may lead to code execution or system compromise.

Executive summary

A critical out-of-bounds write vulnerability in NVIDIA DGX Spark GB10 firmware exposes systems to potential remote code execution and full system compromise.

Vulnerability

This flaw is an out-of-bounds write (CWE-787) within the SROOT firmware. According to the CVSS vector (AV:L/PR:L), the vulnerability requires an attacker to have local access with low privileges to trigger the memory corruption.

Business impact

The potential impact of this vulnerability is severe, as exploitation could lead to arbitrary code execution, unauthorized data tampering, denial of service, or escalation of privileges. With a CVSS score of 7.8 (High), this vulnerability poses a significant threat to the confidentiality, integrity, and availability of the affected hardware systems. Failure to remediate could result in a complete loss of control over the affected DGX units.

Remediation

Immediate Action: Update the NVIDIA DGX Spark GB10 firmware to version OTA0 or later immediately to resolve the vulnerable code path.

Proactive Monitoring: Monitor system logs for unusual kernel activity or unauthorized attempts to access low-level hardware interfaces.

Compensating Controls: Ensure that access to the affected hardware is strictly restricted to authorized personnel only, following the principle of least privilege to mitigate the impact of the local access requirement.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the severity of potential impacts, including code execution and privilege escalation, administrators must prioritize the firmware update to version OTA0. While the vulnerability requires local access, the risk remains high in multi-tenant or shared environments where low-privileged users may interact with the system. Apply the update during the next maintenance window to ensure full protection.

More NVIDIA CVEs

Sources