Vulnerabilities > CVE-2021-33881 - Incorrect Authorization vulnerability in NXP products

047910
CVSS 4.2 - MEDIUM
Attack vector
PHYSICAL
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
high complexity
nxp
CWE-863

Summary

On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) over RFID to bypass a Monotonic Counter protection mechanism. The impact depends on how the anti tear-off feature is used in specific applications such as public transportation, physical access control, etc.

Common Weakness Enumeration (CWE)