Description

Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, information stored in the IC chip may be read or tampered with.

Severity (CVSS)

Base score7
SeverityHigh
VersionCVSS 4.0
VectorCVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Provided byCNA

Weaknesses

  • CWE-325 — Missing cryptographic step

Affected products

VendorProductVersions
Sony CorporationFeliCa IC chipsshipped in or before 2017

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 21 Jul 2026 07:01 UTC.