← Vulnerability feed

Vulnerability record · CVE-2025-33195 · published 25 November 2025

CVE-2025-33195: Nvidia dgx os memory buffer overflow vulnerability

Nvidia · Dgx Os

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause unexpected memory buffer operations. A successful exploit of this vulnerability might lead to data tampering, denial of service, or escalation of privileges.

7.8 CVSS 3.1 High EPSS 0.15% · top 96.7% CWE-119 · Memory buffer overflow
7.8CVSS 3.1 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause unexpected memory buffer operations. A successful exploit of this vulnerability might lead to data tampering, denial of service, or escalation of privileges.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-33195 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2026-24218Nvidia dgx os vulnerabilityNVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be de…EPSS 0.60%7.8CVE-2025-33188Nvidia dgx os improper privilege management vulnerabilityNVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware controls. A successful exploit of t…EPSS 0.16%7.8CVE-2025-33189Nvidia dgx os out-of-bounds write vulnerabilityNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an out-of-bound write. A successful exploit of this v…EPSS 0.18%7.8CVE-2025-33190Nvidia dgx os out-of-bounds write vulnerabilityNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware where an attacker could cause an out-of-bound write. A successful exploit of this vu…EPSS 0.16%7.8CVE-2025-33187Nvidia dgx os improper privilege management vulnerabilityNVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to SoC protected areas. A succe…EPSS 0.18%7.1CVE-2025-33194Nvidia dgx os vulnerabilityNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of input data. A successful explo…EPSS 0.15%5.5CVE-2025-33196Nvidia dgx os vulnerabilityNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploit of this…EPSS 0.14%5.5CVE-2025-33197Nvidia dgx os null pointer dereference vulnerabilityNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a NULL pointer dereference. A successful exploit of t…EPSS 0.17%

Source: NIST National Vulnerability Database (record CVE-2025-33195), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.