NVIDIA DGX Spark SROOT Firmware Resource Reuse Vulnerability Leading to Information Disclosure

Vulnerability

A vulnerability exists in the SROOT firmware of NVIDIA DGX Spark GB10, allowing an attacker to cause a resource to be reused. Exploitation of this vulnerability could result in unauthorized information disclosure.

Impact

Successful exploitation of this vulnerability could lead to unauthorized information disclosure.

Remediation

Users are advised to download and install the latest version of NVIDIA DGX OS from the NVIDIA DGX site.

Added: Nov 25, 2025, 6:24 PM
Updated: Nov 25, 2025, 10:43 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
3.3
remediation
7.7
relevance
1.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.