CVE-2025-33193: Medium severity Nvidia DGX Spark vulnerability
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper validation of integrity. A successful exploit of this vulnerability might lead to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33193?
CVE-2025-33193 has been rated with a high severity level due to potential information disclosure risks.
How do I fix CVE-2025-33193?
To mitigate CVE-2025-33193, it's recommended to update the SROOT firmware to the latest version provided by NVIDIA.
What kind of attack can exploit CVE-2025-33193?
An attacker can exploit CVE-2025-33193 by causing improper validation of integrity, which may compromise sensitive data.
Who is affected by CVE-2025-33193?
Organizations using NVIDIA DGX Spark systems are at risk of CVE-2025-33193 and should assess their exposure.
When was CVE-2025-33193 disclosed?
CVE-2025-33193 was disclosed in 2025, highlighting vulnerabilities in NVIDIA DGX Spark's SROOT firmware.