HomeUpdatesNVIDIA fixes critical vulnerabilities in DGX Spark 

NVIDIA fixes critical vulnerabilities in DGX Spark 

NVIDIA has issued a highly urgent security update for its DGX Spark AI workstation after discovering 14 critical vulnerabilities in the system’s firmware. The vulnerabilities could allow attackers to execute malicious code, bypass critical protections or even cause denial-of-service , (DoS) attacks on systems that form the backbone of advanced artificial intelligence projects.

NVIDIA DGX Spark 

14 vulnerabilities, one critical: What NVIDIA reveals

According to the company, the most severe of the vulnerabilities — listed as CVE-2025-33187— has a CVSS score of 9.3, which places it in the most dangerous category. The issue affects all DGX Spark devices running versions prior to the recent OTA0. Therefore, an immediate upgrade is the only option for organizations relying on this hardware.

See also: Charges of illegal trafficking of Nvidia AI chips in China

The vulnerabilities are located in multiple layers of the DGX Spark GB10 firmware, touching elements such as SROOT, OSROOT , and various physical resource checks. The complexity of this chain of vulnerabilities suggests that malicious actors could, with the right access, manipulate low-level system functions — something that has been considered extremely difficult until now.

How the problems were identified — and why they matter so much

NVIDIA's Offensive Security Research Team was the one who discovered the vulnerabilities, noting that they allow attackers with local or privileged access to breach protected areas in the SoC. The attack could lead to:

  • Arbitrary code execution
  • Bypassing security policies
  • Data theft or corruption
  • DoS attacks
  • Installing backdoors with persistence capabilities
  • Escalation of rights
NVIDIA fixes critical vulnerabilities in DGX Spark 

Given the sensitivity of the AI ​​models and training data typically managed by DGX stations, the potential for a breach could have a huge impact: from loss of intellectual property to manipulation of models supporting critical applications.

OTA0 update fixes all CVEs — but the risk remains

NVIDIA confirms that the new OTA0 update fixes all 14 reported CVEs, closing critical vulnerabilities at all firmware levels. At the same time, it urges all DGX Spark owners to use the official NVIDIA DGX to immediately download and install the update.

See also: NVIDIA NeMo Framework vulnerabilities allow privilege escalation

It is also important to note that some vulnerabilities can be exploited without the need for administrative privileges, especially in environments where users have physical access to the hardware.

What this means for AI companies and research centers

DGX Spark workstations are designed to support demanding AI and machine learning workloads. A successful attack on such a system is not just about downtime; it is about potential compromise:

  • AI business models
  • High-value training data
  • Proprietary algorithms
  • Research results

In an environment where AI models are strategic assets, even a small breach can turn into a blow to millions.

Cybersecurity analysts point out that this disclosure highlights the new reality: AI hardware systems are now high-value targets for attackers seeking access to data, computing resources, or proprietary know-how.

See also: Vulnerability in NVIDIA App for Windows allows code execution

NVIDIA fixes critical vulnerabilities in DGX Spark 

NVIDIA: Stay informed and protected

The company recommends that DGX Spark users:

  • Install the OTA0 update immediately
  • Subscribe to NVIDIA Product Security Bulletins
  • They check regularly for new updates.
  • Report potential issues through the official security channel

AI hardware security becomes a priority

This case is a stark reminder that the hardware that powers AI is not invulnerable. With the proliferation of high-performance systems, firmware-level attacks will become one of the most critical areas in AI security in the coming years.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS