CVE-2025-33189: High severity Nvidia DGX Spark vulnerability
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-bound write. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, information disclosure, or escalation of privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33189?
CVE-2025-33189 is considered a high severity vulnerability due to its potential for code execution and privilege escalation.
What can be exploited in CVE-2025-33189?
CVE-2025-33189 can be exploited to cause an out-of-bound write leading to various impacts including data tampering and denial of service.
How do I fix CVE-2025-33189?
To fix CVE-2025-33189, users should apply the latest firmware updates released by NVIDIA for the DGX Spark system.
Who is affected by CVE-2025-33189?
CVE-2025-33189 affects users of the NVIDIA DGX Spark systems with SROOT firmware.
What could happen if CVE-2025-33189 is successfully exploited?
If successfully exploited, CVE-2025-33189 could lead to code execution, data tampering, or even privilege escalation.