Executive brief
NVIDIA DGX Spark is a high-performance AI computing system used for machine learning and data analytics workloads. A vulnerability in its management module (MM) firmware allows an attacker to read memory outside intended boundaries, potentially exposing sensitive information stored in system memory such as cryptographic keys or configuration data.
Technical details
The vulnerability is an out-of-bounds read flaw in the standalone MM firmware component of NVIDIA DGX Spark. The exact root cause and attack vector are not fully detailed in the available advisory excerpt, but the condition allows an attacker to read memory at arbitrary or unvalidated addresses. Successful exploitation could disclose sensitive data from the firmware or system memory. The severity is assessed as medium (CVSS 6.0), and the vulnerability has not been observed exploited in the wild as of the publication date. Patching information was not available in the provided advisory excerpt.
Affected products
- NVIDIA DGX Spark <UNKNOWN>
Timeline
- 2026-08-25: disclosed