CVE-2026-59776
Received Received - Intake

Missing Cryptographic Step in FeliCa IC Chips

Vulnerability report for CVE-2026-59776, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: JPCERT/CC

Description

Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-21
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sony felica_ic_chip *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-325 The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Missing Cryptographic Step (CWE-325) vulnerability in certain FeliCa IC chips made by Sony and shipped before 2017. The flaw occurs during cryptographic processing where a critical step is missing, weakening security. Attackers could exploit this to read or tamper with data stored on the IC chip.

Detection Guidance

Detection requires checking if your system uses affected FeliCa IC chips shipped before 2017. Contact your service provider or Sony for chip model verification. Physical inspection of IC cards may be needed. No direct network commands are available due to the hardware-level nature of this vulnerability.

Impact Analysis

If you use affected FeliCa IC chips, attackers might steal or alter sensitive data stored on the chip. This could include personal information, payment details, or authentication credentials. Physical access to the chip, such as through theft or skimming, increases risk.

Compliance Impact

This vulnerability could lead to unauthorized reading or tampering of sensitive data stored on affected FeliCa IC chips, which may violate compliance requirements for data protection standards like GDPR or HIPAA. Service providers must assess their systems to mitigate risks and ensure regulatory adherence.

Mitigation Strategies

Immediately contact your service provider for mitigation guidance. Follow Sony's published countermeasures on JVN#40509781. Ensure physical security of IC cards to prevent theft or skimming. Apply any vendor-provided patches or updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59776. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart