CRITICAL🇵🇱 Wersja polska

CVE-2025-33187

CVSS 9.3v3.1pub. 2025-11-25upd. 2025-12-02

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to SoC protected areas. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, denial of service, or escalation of privileges.

🤖 AI Analysis
How it works

The error classified as CWE-269 (Improper Privilege Management) involves insufficient access control in the SROOT component of the DGX Spark GB10 device. An attacker with privileged access to the system can exploit this vulnerability to go beyond normally permitted privilege scope and gain access to protected areas of the SoC. The local vector (AV:L) indicates that exploitation requires access to the local system, however the scope of the attack extends beyond the component boundary (S:C), which increases the potential impact reach.

Impact

Successful exploitation of this vulnerability can lead to arbitrary code execution (RCE), disclosure of sensitive information, data manipulation, denial of service (DoS), or privilege escalation within the protected SoC space.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references – detailed information about patches has been published by NVIDIA at https://nvidia.custhelp.com/app/answers/detail/a_id/5720

Who is affected

NVIDIA DGX Spark GB10 – NVIDIA DGX Spark products and NVIDIA DGX OS; specific versions indicated in the manufacturer's references (https://nvidia.custhelp.com/app/answers/detail/a_id/5720)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Nvidia Dgx Os

    OS
    Nvidia
    all versions
  • Nvidia Dgx Spark

    HW
    Nvidia
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDoS
CWE
References

Related vulnerabilities

CVE-2025-33189HIGH7.8same product

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-boun...

CVE-2025-33188HIGH8.0same product

NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardw...

CVE-2025-33191MEDIUM5.7same product

Firmware OSROOT w urządzeniu NVIDIA DGX Spark GB10 zawiera podatność, która pozwala atakującemu na odczyt niep...

CVE-2025-33192MEDIUM5.7same product

Oprogramowanie SROOT w urządzeniu NVIDIA DGX Spark GB10 zawiera podatność umożliwiającą atakującemu wykonanie ...

CVE-2025-33190MEDIUM6.7same product

Urządzenie NVIDIA DGX Spark GB10 zawiera podatność w oprogramowaniu SROOT, w której atakujący może spowodować ...