ZF Roll Stability Support Plus (RSSPlus) is vulnerable...
Moderate severity
Unreviewed
Published
Feb 14, 2025
to the GitHub Advisory Database
•
Updated Feb 14, 2025
Description
Published by the National Vulnerability Database
Feb 13, 2025
Published to the GitHub Advisory Database
Feb 14, 2025
Last updated
Feb 14, 2025
ZF Roll Stability Support Plus (RSSPlus)
is vulnerable to an authentication bypass vulnerability targeting
deterministic RSSPlus SecurityAccess service seeds, which may allow an
attacker to remotely (proximal/adjacent with RF equipment or via pivot
from J2497 telematics devices) call diagnostic functions intended for
workshop or repair scenarios. This can impact system availability,
potentially degrading performance or erasing software, however the
vehicle remains in a safe vehicle state.
References