Impact
This vulnerability is an unsigned to signed conversion error in the TTSSH2 plugin of Tera Term. When the application attempts to establish an SSH connection to a server set up by an attacker, the conversion flaw causes an out‑of‑bounds read or write. The result is that memory contents adjacent to the intended buffer may be sent to the attacker or used in ways that the program does not anticipate, potentially exposing sensitive data or causing Tera Term to terminate unexpectedly.
Affected Systems
The affected product is the TTSSH2 plugin supplied by the TeraTerm Project. No specific version ranges are listed in the CNA data, so all releases that include the plugin remain potentially vulnerable until the vendor releases a patched version.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability of exploitation currently. The CVSS score of 5.1 reflects a moderate severity, balancing the risk of memory disclosure against the limited attack surface. The vulnerable condition is triggered only when Tera Term initiates an SSH connection, so the attack vector is inferred to be remote with the attacker needing to operate a malicious SSH server and entice a user to connect. Because the issue is not listed in CISA’s KEV catalog, the exposure is not yet proven in the wild, but the potential for memory leakage or a crash remains, warranting timely remediation.
OpenCVE Enrichment