nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-20200 CVE-2017-20200
MEDIUM
Coinomi cleartext transmission
Record summary
CVE-2017-20200 has a selected CVSS score of 6.3 (medium).
Description
A vulnerability has been found in Coinomi up to 1.7.6. This issue affects some unknown processing. Such manipulation leads to cleartext transmission of sensitive information. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The vendor replied with: "(...) there isn't any security implication associated with your findings."
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 23, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Coinomi | CVE List | 1.7.0 | affected |
| 1.7.1 | affected | ||
| 1.7.2 | affected | ||
| 1.7.3 | affected | ||
| 1.7.4 | affected | ||
| 1.7.5 | affected | ||
| 1.7.6 | affected |
References
7VDB-325143 | CTI Indicators (IOB, IOC, TTP)signaturepermissions required
https://vuldb.com/?ctiid.325143 VDB-325143 | Coinomi cleartext transmissionvdb entry
https://vuldb.com/?id.325143 Submit #653875 | COINOMI LTD Coinomi <=1.7.6 Cleartext Transmission of Sensitive Information (information disThird-party advisory
https://vuldb.com/?submit.653875 web.archive.orgbroken linkissue trackingexploit
https://web.archive.org/web/20171013065745/https://github.com/Coinomi/coinomi-android/issues/213 reddit.comrelated
https://www.reddit.com/r/Bitcoin/comments/72yvnj/so_coinomis_official_response_on_the reddit.comrelated
https://www.reddit.com/r/CryptoCurrency/comments/72osq7/security_warning_coinomi_wallet_transmits_all/dnkhpob