NVIDIA DGX Spark SROOT Firmware Memory Buffer Vulnerability

Vulnerability

A vulnerability exists in the SROOT firmware of NVIDIA DGX Spark GB10, allowing an attacker to manipulate memory buffer operations. Exploitation of this vulnerability could result in unauthorized data modification, service disruption, or privilege escalation.

Impact

Successful exploitation may lead to data tampering, denial of service, or unauthorized privilege escalation.

Remediation

Users are advised to update to the latest version of NVIDIA DGX OS, available on the NVIDIA DGX product page.

Added: Nov 25, 2025, 6:26 PM
Updated: Nov 25, 2025, 10:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
7.7
relevance
1.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.