CVE-2025-33190
BaseFortify
Publication date: 2025-11-25
Last updated on: 2025-12-02
Assigner: NVIDIA Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nvidia | dgx_os | * |
| nvidia | dgx_spark | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the SROOT firmware of NVIDIA DGX Spark GB10, where an attacker can cause an out-of-bound write. Exploiting this flaw could allow the attacker to execute arbitrary code, tamper with data, cause denial of service, or escalate their privileges on the affected system.
How can this vulnerability impact me? :
If exploited, this vulnerability can lead to serious impacts including unauthorized code execution, modification of data, disruption of service, and gaining higher privileges than intended, potentially compromising the security and stability of your system.