CVE-2024-12054
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-12054 is a newly disclosed authentication bypass vulnerability affecting ZF's Roll Stability Support Plus (RSSPlus) system. The issue lies in the deterministic RSSPlus SecurityAccess service seeds, which are intended to secure diagnostic functions. An attacker can exploit this vulnerability to call these functions remotely, either proximally using RF equipment or via pivot from J2497 telematics devices. The consequences of this vulnerability include system availability issues, potential performance degradation, and software erasure. However, it's important to note that the vehicle remains in a safe state.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.