Impact
NVIDIA DGX Spark firmware contains an out-of-bounds write vulnerability that can be triggered by a privileged attacker. Exploitation may allow arbitrary code execution, privilege escalation, denial of service, information disclosure, and data tampering, potentially compromising the entire system.
Affected Systems
The affected product is NVIDIA DGX Spark. No specific firmware version ranges are disclosed in the CVE data, so all current releases are presumed vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity vulnerability; the EPSS score is not available and the vulnerability is not listed in CISA KEV. The likely attack vector is a local privileged attacker who can interact with the system firmware, giving them the ability to execute arbitrary code or manipulate data with high privileges.
OpenCVE Enrichment