Home

Description

EN DE

A vulnerability has been found in Coinomi up to 1.7.6. This issue affects some unknown processing. Such manipulation leads to cleartext transmission of sensitive information. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The vendor replied with: "(...) there isn't any security implication associated with your findings."

In Coinomi up to 1.7.6 ist eine Schwachstelle entdeckt worden. Betroffen hiervon ist ein unbekannter Ablauf. Durch das Manipulieren mit unbekannten Daten kann eine cleartext transmission of sensitive information-Schwachstelle ausgenutzt werden. Der Angriff kann remote ausgeführt werden. Das Durchführen eines Angriffs ist mit einer relativ hohen Komplexität verbunden. Das Ausnutzen gilt als schwierig. Der Exploit ist öffentlich verfügbar und könnte genutzt werden.

PUBLISHED Reserved 2025-09-21 | Published 2025-09-23 | Updated 2025-09-23 | Assigner VulDB




MEDIUM: 6.3CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
LOW: 3.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C
LOW: 3.7CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C
2.6AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:C

Problem types

Cleartext Transmission of Sensitive Information

Cryptographic Issues

Timeline

2017-11-08:Advisory disclosed
2025-09-21:VulDB entry created
2025-09-22:VulDB entry last update

Credits

Luke Childs finder

lukechilds (VulDB User) reporter

lukechilds (VulDB User) analyst

References

vuldb.com/?id.325143 (VDB-325143 | Coinomi cleartext transmission) vdb-entry

vuldb.com/?ctiid.325143 (VDB-325143 | CTI Indicators (IOB, IOC, TTP)) signature permissions-required

vuldb.com/?submit.653875 (Submit #653875 | COINOMI LTD Coinomi <=1.7.6 Cleartext Transmission of Sensitive Information (information dis) third-party-advisory

web.archive.org/...ub.com/Coinomi/coinomi-android/issues/213 broken-link issue-tracking

www.reddit.com/...ning_coinomi_wallet_transmits_all/dnkhpob/ related

web.archive.org/...ub.com/Coinomi/coinomi-android/issues/213 exploit issue-tracking

www.reddit.com/...yvnj/so_coinomis_official_response_on_the/ related

cve.org (CVE-2017-20200)

nvd.nist.gov (CVE-2017-20200)

Download JSON