ZF Roll Stability Support Plus (RSSPlus) 
is vulnerable to an authentication bypass vulnerability targeting 
deterministic RSSPlus SecurityAccess service seeds, which may allow an 
attacker to remotely (proximal/adjacent with RF equipment or via pivot 
from J2497 telematics devices) call diagnostic functions intended for 
workshop or repair scenarios. This can impact system availability, 
potentially degrading performance or erasing software, however the 
vehicle remains in a safe vehicle state.
                
            Metrics
Affected Vendors & Products
References
        History
                    Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Fri, 14 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 13 Feb 2025 22:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | ZF Roll Stability Support Plus (RSSPlus) is vulnerable to an authentication bypass vulnerability targeting deterministic RSSPlus SecurityAccess service seeds, which may allow an attacker to remotely (proximal/adjacent with RF equipment or via pivot from J2497 telematics devices) call diagnostic functions intended for workshop or repair scenarios. This can impact system availability, potentially degrading performance or erasing software, however the vehicle remains in a safe vehicle state. | |
| Title | ZF Roll Stability Support Plus (RSSPlus) Authentication Bypass By Primary Weakness | |
| Weaknesses | CWE-305 | |
| References |  | |
| Metrics | cvssV3_1 
 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: icscert
Published: 2025-02-13T22:08:03.541Z
Updated: 2025-02-14T15:58:47.771Z
Reserved: 2024-12-02T19:56:35.074Z
Link: CVE-2024-12054
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-02-14T15:58:43.141Z
 NVD
                        NVD
                    Status : Received
Published: 2025-02-13T23:15:09.823
Modified: 2025-02-13T23:15:09.823
Link: CVE-2024-12054
 Redhat
                        Redhat
                    No data.