Authentication Bypass Vulnerability in ZF Roll Stability Support Plus
CVE-2024-12054
5.9MEDIUM
What is CVE-2024-12054?
ZF Roll Stability Support Plus (RSSPlus) is susceptible to an authentication bypass vulnerability that targets predictable SecurityAccess service seeds. This vulnerability allows attackers, either remotely or through adjacent RF equipment, to invoke diagnostic functions that are typically reserved for workshop or repair scenarios. If exploited, this could degrade system performance or potentially erase software, although the overall safety of the vehicle remains intact.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
RSSPlus 2M 01/08 < 01/23
References
CVSS V4
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
National Motor Freight Traffic Association, Inc. (NMFTA) researchers Ben Gardiner and Anne Zachos reported this vulnerability to CISA.
