CVE-2017-20200

LOW

Coinomi < 1.7.6 - Cleartext Transmission of Sensitive Information

Title source: llm
STIX 2.1

Description

A vulnerability has been found in Coinomi up to 1.7.6. This issue affects some unknown processing. Such manipulation leads to cleartext transmission of sensitive information. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The vendor replied with: "(...) there isn't any security implication associated with your findings."

Scores

CVSS v3 3.7
EPSS 0.0024
EPSS Percentile 15.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-310 CWE-319
Status published
Products (7)
n/a/Coinomi 1.7.0
n/a/Coinomi 1.7.1
n/a/Coinomi 1.7.2
n/a/Coinomi 1.7.3
n/a/Coinomi 1.7.4
n/a/Coinomi 1.7.5
n/a/Coinomi 1.7.6
Published Sep 23, 2025
Tracked Since Feb 18, 2026