Executive brief
NVIDIA DGX Spark is a data center server platform used for AI and machine learning workloads. The UEFI firmware contains a vulnerability that allows a privileged local user to bypass UEFI administrator password protection, potentially enabling unauthorized firmware modifications or system compromise.
Technical details
The vulnerability is a CWE-693 (Protection Mechanism Failure) affecting the UEFI firmware in NVIDIA DGX Spark. A privileged local user can exploit this flaw to circumvent administrator password protection in UEFI, gaining unauthorized access to firmware settings and potentially system-level capabilities. The attack requires local access and elevated privileges. No evidence of active exploitation in the wild has been reported. NVIDIA has published security bulletin 5867 with the technical details and patch information.
Affected products
- NVIDIA DGX Spark <UNKNOWN>
Timeline
- 2026-08-25: disclosed