CVE-2025-33199
Estado: AnalizadaBaja (3.8)—
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause incorrect control flow behavior. A successful exploit of this vulnerability might lead to data tampering.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
- Puntuación base: 3.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.14%
- Percentil entre todas las CVEs puntuadas: 3
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-670
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-33199",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-33199",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-11-25T21:22:54.248408Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@nvidia.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 3.2,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 1.5
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 3.8,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2
}
]
},
"affected": [
{
"source": "psirt@nvidia.com",
"affectedData": [
{
"vendor": "NVIDIA",
"product": "DGX Spark",
"versions": [
{
"status": "affected",
"version": "All versions prior to OTA0"
}
],
"platforms": [
"NVIDIA DGX OS"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-11-25T18:15:51.890",
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33199",
"tags": [
"Third Party Advisory"
],
"source": "psirt@nvidia.com"
},
{
"url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5720",
"tags": [
"Vendor Advisory"
],
"source": "psirt@nvidia.com"
},
{
"url": "https://www.cve.org/CVERecord?id=CVE-2025-33199",
"tags": [
"Third Party Advisory"
],
"source": "psirt@nvidia.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@nvidia.com",
"description": [
{
"lang": "en",
"value": "CWE-670"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause incorrect control flow behavior. A successful exploit of this vulnerability might lead to data tampering."
},
{
"lang": "es",
"value": "NVIDIA DGX Spark GB10 contiene una vulnerabilidad en el firmware SROOT, donde un atacante podría causar un comportamiento incorrecto del flujo de control. Un exploit exitoso de esta vulnerabilidad podría conducir a la manipulación de datos."
}
],
"lastModified": "2026-06-17T09:13:13.610",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:nvidia:dgx_os:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "40EF912C-72C4-4758-9157-169CE92B33C5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:nvidia:dgx_spark:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "76975E53-4E5C-4C6D-85D9-EE2879F960DF"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@nvidia.com"
}