Description
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
Published: 2026-08-25
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Code Execution
Action: Patch Firmware
AI Analysis

Impact

NVIDIA DGX Spark firmware contains an out‑of‑bounds write flaw (CWE‑787) that can be triggered by a privileged attacker. The vulnerability allows memory corruption beyond intended bounds, providing the opportunity for code execution, privilege escalation, denial of service, information disclosure, and data tampering. The primary consequence is that a compromised firmware can execute arbitrary code on the device, undermining confidentiality, integrity, and availability of the entire system.

Affected Systems

Affected systems are NVIDIA DGX Spark devices that run the vulnerable system firmware. No specific firmware revision was supplied in the advisory, so any DGX Spark operating with the firmware before the vendor’s patch remains at risk. The flaw affects all components that rely on the firmware, including OS, drivers, and embedded services.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity vulnerability that threatens code execution. The EPSS metric is not provided, and the issue is currently not listed in CISA’s KEV catalog. Because the flaw requires privileged firmware access, the likely attack vector is an insider or a local attacker who can run firmware‑level code. Consequently, the vulnerability demands high priority remediation and continuous monitoring until patching is complete.

Generated by OpenCVE AI on August 25, 2026 at 22:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the DGX Spark firmware to the vendor‑provided version that contains the out‑of‑bounds write fix
  • Restrict physical access to DGX Spark devices, disable unnecessary remote management interfaces, and enforce strict role‑based access control so that only trusted administrators can modify firmware or run privileged commands
  • Monitor system logs and firmware‑related events for signs of anomalous memory activity, privilege escalation, or denial‑of-service incidents, and respond promptly to any suspicious activity

Generated by OpenCVE AI on August 25, 2026 at 22:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia dgx Spark Uefi
CPEs cpe:2.3:h:nvidia:dgx_spark:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:dgx_spark_uefi:*:*:*:*:*:*:*:*
Vendors & Products Nvidia dgx Spark Uefi

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title DGX Spark Firmware Out‑of‑Bounds Write Enables Code Execution

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Firmware Out-of-Bounds Write Enabling Code Execution on NVIDIA DGX Spark DGX Spark Firmware Out‑of‑Bounds Write Enables Code Execution

Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Firmware Out-of-Bounds Write Enabling Code Execution on NVIDIA DGX Spark
First Time appeared Nvidia
Nvidia dgx Spark
Vendors & Products Nvidia
Nvidia dgx Spark

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Nvidia Dgx Spark Dgx Spark Uefi
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-26T03:56:34.300Z

Reserved: 2026-01-21T19:09:49.054Z

Link: CVE-2026-24262

cve-icon Vulnrichment

Updated: 2026-08-25T19:39:20.601Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T17:17:10.750

Modified: 2026-09-09T13:22:53.927

Link: CVE-2026-24262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:30:17Z

Weaknesses