NVIDIA DGX Spark SROOT Firmware Input Validation Vulnerability Leading to Information Disclosure or Denial-of-Service

Vulnerability

A vulnerability exists in the SROOT firmware of NVIDIA DGX Spark GB10, where improper processing of input data could be exploited by an attacker. This vulnerability may result in information disclosure or a denial-of-service condition.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure or cause a denial-of-service condition, disrupting normal system operations.

Remediation

Users are advised to download and install the latest version of NVIDIA DGX OS from the NVIDIA DGX site. The OTA0 version includes this security update.

Added: Nov 25, 2025, 6:26 PM
Updated: Nov 25, 2025, 10:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
7.7
relevance
1.1
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.