CVE-2024-12054

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 13, 2025
CWE ID 305

Summary

CVE-2024-12054 is a newly disclosed authentication bypass vulnerability affecting ZF's Roll Stability Support Plus (RSSPlus) system. The issue lies in the deterministic RSSPlus SecurityAccess service seeds, which are intended to secure diagnostic functions. An attacker can exploit this vulnerability to call these functions remotely, either proximally using RF equipment or via pivot from J2497 telematics devices. The consequences of this vulnerability include system availability issues, potential performance degradation, and software erasure. However, it's important to note that the vehicle remains in a safe state.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share