NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of input data. A successful exploit of this vulnerability might lead to information disclosure or denial of service.
The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Dgx_os | Nvidia | * | ota0 (excluding) |