CVE-2020-12118

HIGH

The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information f...

Affects 1 product across 1 vendor.

BCS6.0
CVSS 3.18.2
EPSS1.2%
Percentile66th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, no availability impact.
CWE Weakness Definitions
CWE-276: Incorrect Default Permissions

Software sets overly permissive default access rights during installation or resource creation.

Related Attack Patterns (CAPEC)
CAPEC-81 Web Server Logs Tampering
via CWE-276
CAPEC-127 Directory Indexing
via CWE-276
CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
via CWE-276

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability in the keygen protocol implementation of Binance tss-lib before version 1.2.0 allows attackers to generate crafted h1 and h2 parameters, potentially compromising a signing round or obtaining sensitive information.

BSID: BS-2020-GLOBAL-186177-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2020-12118?
A vulnerability in the keygen protocol implementation of Binance tss-lib before version 1.2.0 allows attackers to generate crafted h1 and h2 parameters, potentially compromising a signing round or obtaining sensitive information.
What is the CVSS score for CVE-2020-12118?
CVE-2020-12118 has CVSS 8.2 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N. EPSS: 1.2%.
Is CVE-2020-12118 actively exploited?
No confirmed active exploitation of CVE-2020-12118 as of 2026-05-30.
How do I remediate CVE-2020-12118?
Priority: IMMEDIATE. Advisory: https://github.com/binance-chain/tss-lib/pull/89
What systems are affected by CVE-2020-12118?
CVE-2020-12118 affects: Binance.
Vulnerability Details
CVE IDCVE-2020-12118
BSIDBS-2020-GLOBAL-186177-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Published2020-04-23
Last Modified2024-11-21
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information from other parties.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Attackers can exploit this vulnerability by generating malicious h1 and h2 parameters during the key generation process. This can lead to the compromise of the signing round or the extraction of sensitive information from other participants in the protocol.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Binance Tss-Lib
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 2283 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash91d15b6314c660ca8f1fc76921bd845cda5c34a0de82633c676972358c404e8a71077395bcda3ac14b2e9f1e08ad41c38e413e0bd22746008e6bc6d49ad65ff8
Related CVEs affecting Binance
CVE-2024-31695 9.8 A misconfiguration in the fingerprint authentication mechanism of Binance: BT... CVE-2025-27106 8.8 binance-trading-bot is an automated Binance trading bot with trailing buy/sel... CVE-2024-23660 7.5 The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd14436...
View all Binance CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →