9.3
/ 10
CRITICAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Description
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to SoC protected areas. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, denial of service, or escalation of privileges.
AI Analysis
Privilege escalation vulnerability in NVIDIA DGX Spark GB10 due to SROOT vulnerability, potentially leading to code execution, information disclosure, data tampering, denial of service, or escalation of privileges.
Basic Information
ID
CVE-2025-33187
Source
nvidia
Published
Nov 25, 2025 at 17:57
Modified
Nov 25, 2025 at 20:23
Affected Product
Vendor
NVIDIA
Product
DGX Spark
Version
All versions prior to OTA0
Affected Versions
NVIDIA DGX Spark All versions prior to OTA0
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
NVIDIA
Product
DGX Spark
Version
All versions prior to OTA0