Impact
NVIDIA DGX Spark includes a vulnerability in its standalone MM firmware that permits an out‑of‑bounds read. If an attacker can trigger this flaw, they may be able to read memory beyond the intended buffer boundaries, potentially exposing sensitive data stored on the device. The weakness is categorized as CWE‑125, which focuses on improper handling of memory during read operations.
Affected Systems
Affected systems are NVIDIA DGX Spark devices utilizing the standalone MM firmware. No specific firmware or product version information is provided, so all builds deployed with this firmware are potentially impacted. Exact version details have not been disclosed.
Risk and Exploitability
The CVSS score of 6.0 indicates a moderate severity for this vulnerability. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation at this time. The description does not specify the attack vector; therefore, it is unclear whether the vulnerability is exploitable remotely or only from a local or privileged context. Nonetheless, an attacker who can influence the firmware read operation could gain access to confidential information.
OpenCVE Enrichment