PatchSiren cyber security CVE debrief
CVE-2026-24225 NVIDIA CVE debrief
A vulnerability in NVIDIA DGX Spark's standalone MM firmware could allow an attacker to cause an out-of-bounds read, potentially leading to information disclosure. This CVE was published on 2026-08-25T17:17:10.517Z and was last modified on 2026-09-09T13:22:51.347Z. The vulnerability exists in the standalone MM firmware of NVIDIA DGX Spark, where an attacker could cause an out-of-bounds read. This might lead to information disclosure. The CVSS score is 6 (MEDIUM). Defenders responsible for NVIDIA DGX Spark systems should assess exposure and prioritize verification of affected versions and potential information disclosure risks.
- Vendor
- NVIDIA
- Product
- DGX Spark
- CVSS
- MEDIUM 6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for NVIDIA DGX Spark systems should assess exposure and prioritize verification of affected versions and potential information disclosure risks.
Why it matters
This vulnerability in NVIDIA DGX Spark's standalone MM firmware could allow an attacker to cause an out-of-bounds read, potentially leading to information disclosure. Defenders should assess exposure, verify affected versions, and prioritize patching or updating vulnerable systems to mitigate potential information disclosure risks.
- Information disclosure risk due to out-of-bounds read vulnerability.
- Potential data exposure in affected NVIDIA DGX Spark systems.
- Need for verification of affected versions and system configurations.
- Prioritization of patching or updating vulnerable systems.
Technical summary
The vulnerability exists in the standalone MM firmware of NVIDIA DGX Spark, where an attacker could cause an out-of-bounds read. This might lead to information disclosure. The CVSS score is 6 (MEDIUM). The vulnerability in NVIDIA DGX Spark's standalone MM firmware could allow an attacker to cause an out-of-bounds read, potentially leading to information disclosure. Defenders should assess exposure, verify affected versions, and prioritize patching or updating vulnerable systems to mitigate potential information disclosure risks.
Defensive priority
Defenders should prioritize verifying affected versions and assessing exposure, as the vulnerability's impact is currently limited to potential information disclosure.
Recommended defensive actions
- Verify if the system is using an affected version of NVIDIA DGX Spark's standalone MM firmware.
- Assess exposure based on the system's current configuration and deployment context.
- Monitor for potential information disclosure resulting from this vulnerability.
- Consider applying patches or updates provided by NVIDIA to address the vulnerability.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 6 (MEDIUM) and potential impact on information disclosure. However, specific details on affected versions and exploitation are limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-24225 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-24225
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-24225 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24225
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/NVIDIA/product-security/tree/main/2026/5867
[email protected] - Product
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.