Monotonic Counter Bypass Vulnerability in NXP MIFARE Ultralight and NTAG Cards
CVE-2021-33881

4.2MEDIUM

Key Information:

Vendor

Nxp

Vendor
CVE Published:
6 June 2021

What is CVE-2021-33881?

On NXP MIFARE Ultralight and NTAG cards, attackers can exploit a 'tear off' attack during write operations over RFID, circumventing the Monotonic Counter protection mechanism. This vulnerability allows for unauthorized data manipulation, which can severely impact applications that rely on the anti tear-off feature, such as public transportation and physical access control systems. The implications of this vulnerability are significant, especially in environments where security is paramount.

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.