Improper Validation of Integrity Check Value
CVE-2025-33193
Summary
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper validation of integrity. A successful exploit of this vulnerability might lead to information disclosure.
- LOW
- LOCAL
- NONE
- CHANGED
- NONE
- NONE
- LOW
- LOW
CWE-354 - Improper Validation of Integrity Check Value
The software does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
References
Advisory Timeline
- Published