CVE-2025-33196: Medium severity Nvidia DGX Spark vulnerability
Published Nov 25, 2025
·Updated
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploit of this vulnerability might lead to information disclosure.
Affected Software
3 affected components
Nvidia DGX Spark
All of the following
Nvidia DGX OS
Nvidia DGX Spark
Event History
Nov 25, 2025
CVE Published
via MITRE·05:59 PM
Data Sourced
via MITRE·05:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-33196?
The severity of CVE-2025-33196 is considered high due to the potential for information disclosure.
2
How do I fix CVE-2025-33196?
To fix CVE-2025-33196, apply the latest firmware updates provided by NVIDIA for the DGX Spark.
3
Who is affected by CVE-2025-33196?
CVE-2025-33196 affects users of NVIDIA DGX Spark systems.
4
What type of vulnerability is CVE-2025-33196?
CVE-2025-33196 is a resource reuse vulnerability in the SROOT firmware of NVIDIA DGX Spark.
5
What could be the consequences of exploiting CVE-2025-33196?
Exploiting CVE-2025-33196 may lead to unauthorized information disclosure.