CVE-2025-27839 - Tangem SDK Offline Wallet Attestation Verification Bypass
CVE ID : CVE-2025-27839
Published : March 8, 2025, 12:15 a.m. | 3 hours, 8 minutes ago
Description : operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuineness check) that causes verification results to be disregarded during the first scan of a card. Exploitation may not have been possible.
Severity: 3.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : March 8, 2025, 12:15 a.m. | 3 hours, 8 minutes ago
Description : operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuineness check) that causes verification results to be disregarded during the first scan of a card. Exploitation may not have been possible.
Severity: 3.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...