Database/Firmware, BMC & network fabric
NVIDIA DGX Spark: UEFI administrator password protection can be bypassed by a privileged local user
Impact
A privileged local user on a DGX Spark can bypass the administrator password that is supposed to gate UEFI setup, per NVIDIA's advisory (a CWE-693 protection-mechanism failure). The password exists so that host-level root and firmware-level control stay separate: bypassing it lets someone who already owns the OS also change boot configuration and firmware settings. NVIDIA scores integrity impact high with a scope change and no confidentiality or availability impact, which matches a settings-tampering outcome rather than data theft. Firmware-level settings survive an OS reinstall, so this is the kind of change that outlives whatever cleanup an operator does at the software layer.
Who can reach it
Local access with high privileges already held - effectively an OS administrator or root on the DGX Spark. No network path and no user interaction are described.
What to do
Apply the DGX Spark firmware update from NVIDIA's advisory (product-security bulletin 5867, which also covers CVE-2026-24225); the record here does not name a fixed firmware version. A UEFI update means taking the system out of service for the flash and reboot rather than a live patch. Until then, treat the UEFI password as ineffective against anyone who already holds root, and control who has that.
References
Related entries
- Infineon TPM firmware (RSA key generation): RSA keys generated inside affected Infineon TPMs are factorableCVE-2017-15361 · Infineon TPM firmware (RSA key generation)Medium
- STMicroelectronics ST33 TPM (ECDSA timing): Discrete TPM leaks ECDSA nonce data through timing, allowing private keyCVE-2019-16863 · STMicroelectronics ST33 TPM (ECDSA timing)Medium
- Arista EOS (EVPN VXLAN MAC/IP binding): Malformed packets create incorrect MAC-to-IP bindings in an EVPN VXLAN fabricCVE-2020-26569 · Arista EOS (EVPN VXLAN MAC/IP binding)Medium
- Arista EOS (802.1X on access/trunk ports): With 802.1X configured on access or trunk ports and routing enabled on theCVE-2023-5502 · Arista EOS (802.1X on access/trunk ports)Medium
- AMD SEV firmware - RMP protection bypass: An access-control failure in SEV firmware lets a malicious hypervisor bypassCVE-2025-29948 · AMD SEV firmware - RMP protection bypassMedium
- AMD SEV firmware - improper initialization corrupting RMP-covered memory: An initialization defect in SEV firmware letsCVE-2025-29952 · AMD SEV firmware - improper initialization corrupting RMP-covered memoryMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.