Impact
NVIDIA DGX Spark firmware contains an out‑of‑bounds write flaw (CWE‑787) that can be triggered by a privileged attacker. The vulnerability allows memory corruption beyond intended bounds, providing the opportunity for code execution, privilege escalation, denial of service, information disclosure, and data tampering. The primary consequence is that a compromised firmware can execute arbitrary code on the device, undermining confidentiality, integrity, and availability of the entire system.
Affected Systems
Affected systems are NVIDIA DGX Spark devices that run the vulnerable system firmware. No specific firmware revision was supplied in the advisory, so any DGX Spark operating with the firmware before the vendor’s patch remains at risk. The flaw affects all components that rely on the firmware, including OS, drivers, and embedded services.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity vulnerability that threatens code execution. The EPSS metric is not provided, and the issue is currently not listed in CISA’s KEV catalog. Because the flaw requires privileged firmware access, the likely attack vector is an insider or a local attacker who can run firmware‑level code. Consequently, the vulnerability demands high priority remediation and continuous monitoring until patching is complete.
OpenCVE Enrichment