Impact
NVIDIA DGX Spark firmware contains a NULL pointer dereference that a privileged attacker could exploit. If successfully triggered, this flaw can lead to arbitrary code execution, elevation of privileges, denial of service, information disclosure, and data tampering. The vulnerability stems from improper null‑check handling in the firmware code, classed as a NULL pointer dereference weakness.
Affected Systems
The affected product is NVIDIA DGX Spark. Specific firmware versions impacted are not listed in the advisory, so any DGX Spark system running the exposed firmware may be vulnerable.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity. EPSS is not available and the issue is not listed in CISA KEV, suggesting limited public exploitation data. The likely attack vector requires an attacker with privileged or local access to the device, such as a maintenance engineer or someone who can modify firmware. Any successful exploitation could compromise system integrity and availability.
OpenCVE Enrichment