Database/Firmware, BMC & network fabric
NVIDIA DGX Spark: out-of-bounds read in standalone MM firmware discloses information across a scope boundary
Impact
NVIDIA reports an out-of-bounds read in the standalone MM firmware on DGX Spark, with information disclosure as the outcome. The CVSS vector carries a scope change, meaning what leaks is data belonging to a component outside the one the attacker already controls - firmware-resident memory the OS is not supposed to see. There is no integrity or availability impact scored, so this is a read primitive, not a takeover. The record given here does not describe which structures are readable or what secrets could be recovered, so treat it as a disclosure of firmware memory of unknown sensitivity.
Who can reach it
Local, with high privileges already held on the DGX Spark - an OS administrator or root reaching the firmware interface. No remote path is described.
What to do
Apply the DGX Spark firmware update referenced in NVIDIA's advisory (product-security bulletin 5867, shared with CVE-2026-47624); no fixed firmware version appears in this record. Flashing requires the system out of service for the update and reboot. Given that exploitation already requires privileged local access, this can reasonably ride along with the next scheduled firmware maintenance rather than driving its own window.
References
Related entries
- NVIDIA DGX Spark: UEFI administrator password protection can be bypassed by a privileged local userCVE-2026-47624 · NVIDIA DGX Spark (UEFI administrator password protection)Medium
- Infineon TPM firmware (RSA key generation): RSA keys generated inside affected Infineon TPMs are factorableCVE-2017-15361 · Infineon TPM firmware (RSA key generation)Medium
- STMicroelectronics ST33 TPM (ECDSA timing): Discrete TPM leaks ECDSA nonce data through timing, allowing private keyCVE-2019-16863 · STMicroelectronics ST33 TPM (ECDSA timing)Medium
- Arista EOS (EVPN VXLAN MAC/IP binding): Malformed packets create incorrect MAC-to-IP bindings in an EVPN VXLAN fabricCVE-2020-26569 · Arista EOS (EVPN VXLAN MAC/IP binding)Medium
- Arista EOS (802.1X on access/trunk ports): With 802.1X configured on access or trunk ports and routing enabled on theCVE-2023-5502 · Arista EOS (802.1X on access/trunk ports)Medium
- AMD SEV firmware - RMP protection bypass: An access-control failure in SEV firmware lets a malicious hypervisor bypassCVE-2025-29948 · AMD SEV firmware - RMP protection bypassMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.