NVIDIA DGX Spark Out-of-Bounds Write Vulnerability in SROOT Firmware Allowing Code Execution and Privilege Escalation

Vulnerability

A vulnerability has been identified in the SROOT firmware of NVIDIA DGX Spark GB10, where an out-of-bounds write could be exploited by an attacker. This vulnerability affects all versions prior to OTA0. A successful exploit may lead to unauthorized code execution, tampering with data, denial of service, disclosure of sensitive information, or unauthorized escalation of privileges.

Impact

Exploitation of this vulnerability could result in code execution, unauthorized access to sensitive information, unauthorized data modification, a denial-of-service condition, or an escalation of privileges.

Remediation

Users are advised to download and install the latest version of NVIDIA DGX OS from the NVIDIA DGX site.

Added: Nov 25, 2025, 6:30 PM
Updated: Nov 25, 2025, 10:49 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
7.7
relevance
1.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.