CVE 9.3 CRITICAL

CVE-2025-33187_CVE-2025-33187

9.3 / 10
CRITICAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to SoC protected areas. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, denial of service, or escalation of privileges.

AI Analysis

Privilege escalation vulnerability in NVIDIA DGX Spark GB10 due to SROOT vulnerability, potentially leading to code execution, information disclosure, data tampering, denial of service, or escalation of privileges.

Basic Information

ID CVE-2025-33187
Source nvidia
Published Nov 25, 2025 at 17:57
Modified Nov 25, 2025 at 20:23

Affected Product

Vendor NVIDIA
Product DGX Spark
Version All versions prior to OTA0
Affected Versions NVIDIA DGX Spark All versions prior to OTA0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor NVIDIA
Product DGX Spark
Version All versions prior to OTA0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.