CVE-2025-33191: Input Validation
Published Nov 25, 2025
·Updated
NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read. A successful exploit of this vulnerability might lead to denial of service.
Affected Software
3 affected components
Nvidia DGX Spark
All of the following
Nvidia DGX OS
Nvidia DGX Spark
Event History
Nov 25, 2025
CVE Published
via MITRE·05:58 PM
Data Sourced
via MITRE·05:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-33191?
CVE-2025-33191 is considered a medium severity vulnerability as it can lead to denial of service.
2
How do I fix CVE-2025-33191?
To fix CVE-2025-33191, ensure that your NVIDIA DGX Spark firmware is updated to the latest version provided by NVIDIA.
3
What type of attack does CVE-2025-33191 facilitate?
CVE-2025-33191 could facilitate attacks that result in an invalid memory read and subsequent denial of service.
4
Which systems are affected by CVE-2025-33191?
CVE-2025-33191 affects the NVIDIA DGX Spark systems that utilize OSROOT firmware.
5
Can CVE-2025-33191 be exploited remotely?
Yes, CVE-2025-33191 can potentially be exploited by an attacker to cause a denial of service.