Description
Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.
Published: 2026-07-21
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing cryptographic step (CWE‑325) in Sony FeliCa IC chips shipped in or before 2017 permits an attacker to read or tamper with data stored on the chip, resulting in confidentiality and integrity compromise.

Affected Systems

The vulnerability affects Sony FeliCa IC chips introduced during or before 2017, as referenced by Sony’s official advisory and JVN article.

Risk and Exploitability

The CVSS score of 7 indicates medium‑high severity, while an EPSS of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV, implying it is not yet widely exploited. Likely exploitation would require direct physical access or a specialized interface to the chip, as no remote attack vector is disclosed in the available data.

Generated by OpenCVE AI on July 30, 2026 at 18:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by Sony for FeliCa IC chips, as detailed in the official advisory.
  • If an update is unavailable, restrict physical access and enforce strict authentication for any interface communicating with the chip.
  • Perform a full inventory of all devices using the affected chip versions and plan replacements where necessary.

Generated by OpenCVE AI on July 30, 2026 at 18:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Missing Cryptographic Step in Sony FeliCa IC Chips Enables Data Breach

Wed, 29 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Missing Cryptographic Step Allows Unauthorized Access to FeliCa IC Chip Data

Fri, 24 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Missing Cryptographic Step Allows Unauthorized Access to FeliCa IC Chip Data

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Sony
Sony felica Ic Chips
Vendors & Products Sony
Sony felica Ic Chips

Tue, 21 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.
Weaknesses CWE-325
References
Metrics cvssV3_0

{'score': 6.8, 'vector': 'CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Sony Felica Ic Chips
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-07-21T13:26:02.801Z

Reserved: 2026-07-09T08:23:34.922Z

Link: CVE-2026-59776

cve-icon Vulnrichment

Updated: 2026-07-21T13:25:39.575Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T18:15:13Z

Weaknesses
  • CWE-325

    Missing Cryptographic Step