CVE-2021-32033 affects Protectimus SLIM NFC 70 devices and firmware, allowing a "Time Traveler" attack. This vulnerability enables an unauthenticated attacker with brief physical access to manipulate the device's internal clock, generate future time-based one-time passwords (TOTPs), and then reset the clock, effectively pre-generating valid future TOTPs. Rated Medium (CVSS 4.6), the attack requires physical proximity (AV:P) but is low complexity (AC:L) and results in high confidentiality impact (C:H). There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.01CPE matchmatch criteria | cpe:2.3:o:protectimus:slim_nfc_70_firmware:10.01:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.