CVE-2026-24225: Medium severity Nvidia DGX Spark vulnerability
Published Aug 25, 2026
·Updated
NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure.
Affected Software
1 affected component
Nvidia DGX Spark
Event History
Aug 25, 2026
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attack vector is local and requires high privileges. No user interaction is required.
2
What is the expected impact of a successful exploit?
A successful exploit may disclose information through an out-of-bounds read. The provided scoring indicates high confidentiality impact, with no integrity or availability impact.