Vulnerability Details CVE-2026-24225
NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 7.1%
CVSS Severity
CVSS v3 Score 6.0
Products affected by CVE-2026-24225
-
cpe:2.3:h:nvidia:dgx_spark:-
-
cpe:2.3:o:nvidia:dgx_spark_uefi:-
-
cpe:2.3:o:nvidia:dgx_spark_uefi:1.110.12