CVE-2025-33192
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an arbitrary memory read. A successful exploit of this vulnerability might lead to denial of service.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.7
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L
- EPSS probability
- 0.14%
- CWE
- CWE-690
- Published
- 2025-11-25
- Last modified
- 2026-03-13
Affected products
- NVIDIA DGX Spark
Weakness type
Related vulnerabilities
- CVE-2026-24160 — NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an ...
- CVE-2026-44638 — libsixel: NULL pointer dereference
- CVE-2026-24411 — iccDEV has Undefined Behavior and Null Pointer Deference in CIccTagXmlSegmentedCurve::ToXml()
- CVE-2026-24410 — iccDEV has Undefined Behavior and Null Pointer Deference in CIccProfileXml::ParseBasic()
- CVE-2026-24409 — iccDEV has Undefined Behavior and Null Pointer Deference in CIccTagXmlFloatNum<>::ParseXml()
- CVE-2026-24404 — iccDEV has Null Pointer Deference and Undefined Behavior in CIccXmlArrayType()
- CVE-2026-21689 — iccDEV has Type Confusion in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cpp
- CVE-2026-21502 — NULL Pointer Dereference in iccDEV XML Tag Parser