Impact
NVIDIA DGX Spark has a firmware weakness in UEFI that allows a local user with sufficient permissions to bypass the administrator password guard. This breach removes the intended restriction on UEFI configuration and could enable unauthorized changes to boot or firmware settings that would normally require administrator authentication.
Affected Systems
The vulnerability affects NVIDIA DGX Spark platforms. No specific firmware or platform version numbers are provided in the listing.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity, while the EPSS score is not available and the vulnerability is not currently listed in CISA KEV. Based on the description, it is inferred that the attack vector requires local physical or privileged access to the device, which limits the exposed threat surface but still poses a significant risk if an insider or attacker gains local control.
OpenCVE Enrichment