PT-2025-48048 · Nvidia · Dgx Spark Gb10

Published

2025-11-25

·

Updated

2026-01-02

·

CVE-2025-33187

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NVIDIA DGX Spark GB10
Description The NVIDIA DGX Spark GB10 contains a flaw in the SROOT component. An attacker with privileged access could potentially gain access to System on a Chip (SoC) protected areas. A successful exploit may lead to code execution, information disclosure, data tampering, denial of service, or escalation of privileges. The potential impact on AI training workloads and sensitive model data is significant.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

LPE

RCE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-14807
CVE-2025-33187

Affected Products

Dgx Spark Gb10