Back to overview

CVE-2026-59776

HIGH
7.0
CVSS 4.0
Description
Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.

Metadata

CVE ID
CVE-2026-59776
State
PUBLISHED
Assigner
jpcert
Reserved
2026-07-09 08:23 UTC
Published
2026-07-21 03:06 UTC
Last updated
2026-07-21 03:06 UTC
Primary CWE
CWE-325
Missing cryptographic step
Vendor / Product
Sony Corporation / FeliCa IC chips
Sources
cve.org  ·  NVD

Severity & Metrics

7.0 HIGH CVSS 4.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products (1)
VendorProductPlatformVersions
Sony Corporation FeliCa IC chips shipped in or before 2017
Weakness (CWE)
CWESourceDescription
CWE-325 cna Missing cryptographic step
CVSS scores (2)
ScoreSeverityVersionSourceVector
7.0 HIGH 4.0 cna CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
6.8 MEDIUM 3.0 cna CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview