{"api_version":"1","generated_at":"2026-07-23T15:44:09+00:00","cve":"CVE-2021-33648","urls":{"html":"https://cve.report/CVE-2021-33648","api":"https://cve.report/api/cve/CVE-2021-33648.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-33648","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-33648"},"summary":{"title":"CVE-2021-33648","description":"When performing the inference shape operation of Affine, Concat, MatMul, ArgMinMax, EmbeddingLookup, and Gather operators, if the input shape size is 0, it will access data outside of bounds of shape which allocated from heap buffers.","state":"PUBLIC","assigner":"securities@openeuler.org","published_at":"2022-06-27 17:15:00","updated_at":"2022-07-07 16:03:00"},"problem_types":["CWE-125"],"metrics":[],"references":[{"url":"https://gitee.com/mindspore/community/blob/master/security/security_advisory_list/mssa-2021-007_en.md","name":"https://gitee.com/mindspore/community/blob/master/security/security_advisory_list/mssa-2021-007_en.md","refsource":"MISC","tags":[],"title":"security/security_advisory_list/mssa-2021-007_en.md · MindSpore/community - Gitee.com","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-33648","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-33648","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"33648","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mindspore","cpe5":"mindspore","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"openeuler","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-33648","ASSIGNER":"securities@openeuler.org","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"openEuler:mindspore","version":{"version_data":[{"version_value":">= 1.1.0, < 1.3.0"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-125 Out-of-bounds Read"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://gitee.com/mindspore/community/blob/master/security/security_advisory_list/mssa-2021-007_en.md","url":"https://gitee.com/mindspore/community/blob/master/security/security_advisory_list/mssa-2021-007_en.md"}]},"description":{"description_data":[{"lang":"eng","value":"When performing the inference shape operation of Affine, Concat, MatMul, ArgMinMax, EmbeddingLookup, and Gather operators, if the input shape size is 0, it will access data outside of bounds of shape which allocated from heap buffers."}]}},"nvd":{"publishedDate":"2022-06-27 17:15:00","lastModifiedDate":"2022-07-07 16:03:00","problem_types":["CWE-125"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mindspore:mindspore:*:*:*:*:*:openeuler:*:*","versionStartIncluding":"1.1.0","versionEndExcluding":"1.3.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"33648","Ordinal":"209059","Title":"CVE-2021-33648","CVE":"CVE-2021-33648","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"33648","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}