Impact
The TTSSH2 plugin in Tera Term has an improper handling of length parameters that can lead to out‑of‑bounds read and write during SSH negotiation with a server controlled by an attacker. When Tera Term attempts to establish a connection, portions of memory adjacent to the expected buffer may be exposed and sent to the malicious host, enabling the attacker to obtain sensitive data or cause the client to crash.
Affected Systems
Affected product is the TTSSH2 SSH client plugin of Tera Term, provided by the TeraTerm Project. No specific version information is supplied in the advisory; all releases of the plugin before the advisory are potentially vulnerable.
Risk and Exploitability
Risk: The CVSS score of 5.1 indicates a moderate severity primarily due to potential information disclosure and application instability. The EPSS metric shows an exploitation probability of less than 1%, and the vulnerability is not listed in CISA's KEV catalog, implying limited active exploitation. The most realistic attack scenario is remote: an attacker hosts a malicious SSH server and lures or coerces a user to connect with Tera Term. If the connection is established, the plugin’s out‑of‑bounds read/write could expose sensitive memory contents or cause an unexpected termination. No public exploits have been reported and the vulnerability requires the user to initiate contact with an attacker‑controlled server, so overall risk is moderate but not critical.
OpenCVE Enrichment