NVIDIA DGX Spark SROOT Firmware Integrity Validation Vulnerability Leading to Information Disclosure
Vulnerability
A vulnerability exists in the SROOT firmware of NVIDIA DGX Spark GB10, where improper validation of integrity allows for potential information disclosure. This issue affects all versions prior to OTA0.
Impact
Exploitation of this vulnerability could result in unauthorized information disclosure.
Remediation
Users are advised to download and install the latest version of NVIDIA DGX OS from the NVIDIA DGX site.
Added: Nov 25, 2025, 6:27 PM
Updated: Nov 25, 2025, 11:00 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
3.3remediation
7.7relevance
1.2threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
