CVE-2025-33194
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of input data. A successful exploit of this vulnerability might lead to information disclosure or denial of service.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- Base score: 7.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.15%
- Percentile among all scored CVEs: 4
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1068Exploitation for Privilege Escalationprivilege escalation95 % - Primary impact
T1005Data from Local Systemcollection85 % - Secondary impact
T1499.004Application or System Exploitationimpact80 %
AV:L + PR:L sin UI:N indica escalada local (T1068). SROOT firmware + acceso local permite leer datos sensibles (T1005) y causar DoS (T1499.004) por procesamiento impropio de entrada en dispositivo de inteligencia artificial.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
CWEs
- CWE-180
References
Raw JSON (NVD)
Show
{
"id": "CVE-2025-33194",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-33194",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-11-25T19:38:45.751294Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@nvidia.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.7,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.5
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "psirt@nvidia.com",
"affectedData": [
{
"vendor": "NVIDIA",
"product": "DGX Spark",
"versions": [
{
"status": "affected",
"version": "All versions prior to OTA0"
}
],
"platforms": [
"NVIDIA DGX OS"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-11-25T18:15:51.113",
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33194",
"tags": [
"Third Party Advisory"
],
"source": "psirt@nvidia.com"
},
{
"url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5720",
"tags": [
"Vendor Advisory"
],
"source": "psirt@nvidia.com"
},
{
"url": "https://www.cve.org/CVERecord?id=CVE-2025-33194",
"tags": [
"Third Party Advisory"
],
"source": "psirt@nvidia.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@nvidia.com",
"description": [
{
"lang": "en",
"value": "CWE-180"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of input data. A successful exploit of this vulnerability might lead to information disclosure or denial of service."
},
{
"lang": "es",
"value": "NVIDIA DGX Spark GB10 contiene una vulnerabilidad en el firmware SROOT, donde un atacante podría causar un procesamiento incorrecto de los datos de entrada. Un exploit exitoso de esta vulnerabilidad podría llevar a la revelación de información o a la denegación de servicio."
}
],
"lastModified": "2026-06-17T09:13:13.070",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:nvidia:dgx_os:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "40EF912C-72C4-4758-9157-169CE92B33C5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:nvidia:dgx_spark:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "76975E53-4E5C-4C6D-85D9-EE2879F960DF"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@nvidia.com"
}