CVE-2024-12054

ZF Roll Stability Support Plus (RSSPlus) 
is vulnerable to an authentication bypass vulnerability targeting 
deterministic RSSPlus SecurityAccess service seeds, which may allow an 
attacker to remotely (proximal/adjacent with RF equipment or via pivot 
from J2497 telematics devices) call diagnostic functions intended for 
workshop or repair scenarios. This can impact system availability, 
potentially degrading performance or erasing software, however the 
vehicle remains in a safe vehicle state.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H
icscertCNA
5.4 MEDIUM
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H
CISA-ADPADP
---
---