CVE-2024-12054

ZF Roll Stability Support Plus (RSSPlus) is vulnerable to an authentication bypass vulnerability targeting deterministic RSSPlus SecurityAccess service seeds, which may allow an attacker to remotely (proximal/adjacent with RF equipment or via pivot from J2497 telematics devices) call diagnostic functions intended for workshop or repair scenarios. This can impact system availability, potentially degrading performance or erasing software, however the vehicle remains in a safe vehicle state.
Configurations

No configuration.

History

13 Feb 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-13 23:15

Updated : 2025-02-13 23:15


NVD link : CVE-2024-12054

Mitre link : CVE-2024-12054

CVE.ORG link : CVE-2024-12054


JSON object : View

Products Affected

No product.

CWE
CWE-305

Authentication Bypass by Primary Weakness