CyberRota Analysis
AI-GeneratedThe TTSSH2 plugin of Tera Term is vulnerable to an unsigned to signed conversion error, which can lead to out-of-bounds read/write operations during SSH connections to malicious servers. This vulnerability may result in the unintended transmission of adjacent memory contents, potentially exposing sensitive information and causing abnormal behavior or crashes in Tera Term. Organizations using Tera Term for SSH connections should prioritize addressing this issue to mitigate potential data leaks and service disruptions.
Original NVD Description
Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.