CVE-2021-33881
On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) over RFID to bypass a Monotonic Counter protection mechanism. The impact depends on how the anti tear-off feature is used in specific applications such as public transportation, physical access control, etc.
Published:Jun 6, 2021
Last Modified:Nov 21, 2024
EPS:Jun 6, 2021
EPSS Score:0.0006
CVSS Score:4.2
Affected Products
Vendor
Product
Action
Vendor
Nxp
Product
Mifare Ultralight C
Nxp
Mifare Ultralight C
Vendor
Nxp
Product
Mifare Ultralight C Firmware
Nxp
Mifare Ultralight C Firmware
Vendor
Nxp
Product
Mifare Ultralight Ev1
Nxp
Mifare Ultralight Ev1
Vendor
Nxp
Product
Mifare Ultralight Ev1 Firmware
Nxp
Mifare Ultralight Ev1 Firmware
Vendor
Nxp
Product
Mifare Ultralight Nano
Nxp
Mifare Ultralight Nano
Vendor
Nxp
Product
Mifare Ultralight Nano Firmware
Nxp
Mifare Ultralight Nano Firmware
Vendor
Nxp
Product
Ntag 210
Nxp
Ntag 210
Vendor
Nxp
Product
Ntag 210 Firmware
Nxp
Ntag 210 Firmware
Vendor
Nxp
Product
Ntag 212
Nxp
Ntag 212
Vendor
Nxp
Product
Ntag 212 Firmware
Nxp
Ntag 212 Firmware
Vendor
Nxp
Product
Ntag 213
Nxp
Ntag 213
Vendor
Nxp
Product
Ntag 213 Firmware
Nxp
Ntag 213 Firmware
Vendor
Nxp
Product
Ntag 215
Nxp
Ntag 215
Vendor
Nxp
Product
Ntag 215 Firmware
Nxp
Ntag 215 Firmware
Vendor
Nxp
Product
Ntag 216
Nxp
Ntag 216
Vendor
Nxp
Product
Ntag 216 Firmware
Nxp
Ntag 216 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
