CVE-2025-33200: Low severity Nvidia DGX Spark vulnerability
Published Nov 25, 2025
·Updated
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploit of this vulnerability might lead to information disclosure.
Affected Software
3 affected components
Nvidia DGX Spark
All of the following
Nvidia DGX OS
Nvidia DGX Spark
Event History
Nov 25, 2025
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-33200?
CVE-2025-33200 is classified as a medium severity vulnerability due to its potential for information disclosure.
2
How do I fix CVE-2025-33200?
To mitigate CVE-2025-33200, update the SROOT firmware to the latest version released by NVIDIA.
3
What types of attacks can CVE-2025-33200 enable?
CVE-2025-33200 could enable attackers to exploit resource reuse, leading to potential information leakage.
4
Which software is affected by CVE-2025-33200?
CVE-2025-33200 specifically affects the NVIDIA DGX Spark systems.
5
Is CVE-2025-33200 actively being exploited?
As of the latest reports, there have been no confirmed active exploits of CVE-2025-33200 in the wild.