Impact
A missing cryptographic step (CWE‑325) in Sony FeliCa IC chips shipped in or before 2017 permits an attacker to read or tamper with data stored on the chip, resulting in confidentiality and integrity compromise.
Affected Systems
The vulnerability affects Sony FeliCa IC chips introduced during or before 2017, as referenced by Sony’s official advisory and JVN article.
Risk and Exploitability
The CVSS score of 7 indicates medium‑high severity, while an EPSS of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV, implying it is not yet widely exploited. Likely exploitation would require direct physical access or a specialized interface to the chip, as no remote attack vector is disclosed in the available data.
OpenCVE Enrichment