CVE Identifier: CVE-2025-33187 NVD Published Date: 11/25/2025 Description: - NVIDIA DGX Spark GB10 contains a vulnerability in SROOT. An attacker could use privileged access to gain access to SoC protected areas. A successful exploit could lead to code execution, information disclosure, data tampering, denial of service, or escalation of privileges. Severity: - CVSS 3.x Severity: 9.3 CRITICAL - Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Weakness Enumeration: CWE-269 - Improper Privilege Management References: - NVIDIA Corporation - NVIDIA Corporation - CVE.org