Skip to content
AutoST by Zyberum GmbH
Menu
Free toolUDS

UDS Negative Response Code Decoder

Decode a UDS negative response in a second: paste 7F 27 35 or a bare code and get the ISO 14229 name, the rejected service and what it means on the bench. Full NRC table.

Updated This page as Markdown

In short

This tool decodes UDS negative response codes (NRCs) per ISO 14229-1 Annex A. Paste a complete negative response such as 7F 27 35, or a bare code such as 33, and it shows the ISO name, the service that was rejected and what the code usually means when you test an ECU. The full table below the tool is searchable and includes the codes used by the Authentication service (0x29).

Paste the full response (7F 27 35) or just the code (35). Hex, spaces optional.

Decoded

0x35 invalidKey

Rejected service: 0x27 SecurityAccess

The key sent for SecurityAccess did not match the seed. Count these: a weak implementation does not limit attempts.

All negative response codes

CodeISO nameWhat it means on the bench
0x10generalRejectThe ECU rejected the request without a more specific reason. Often a catch-all in the server implementation.
0x11serviceNotSupportedThe service identifier is unknown to this ECU, in any session. Useful for enumeration: the service does not exist here.
0x12subFunctionNotSupportedThe service exists but this sub-function does not, in any session.
0x13incorrectMessageLengthOrInvalidFormatWrong number of bytes for this request. Also what a well-behaved ECU should answer to most fuzzed messages.
0x14responseTooLongThe response would exceed the transport layer limit.
0x21busyRepeatRequestThe ECU is busy; the tester may repeat the request later.
0x22conditionsNotCorrectA precondition is not met, for example vehicle speed, engine running or a required session or state.
0x24requestSequenceErrorThe request came out of order, for example a SecurityAccess key without a preceding seed request, or TransferData without RequestDownload.
0x25noResponseFromSubnetComponentA gateway forwarded the request but the target ECU did not answer.
0x26failurePreventsExecutionOfRequestedActionA failure in the ECU (for example a stored fault) prevents the action.
0x31requestOutOfRangeA parameter is outside the valid range: an unknown DID or RID, an invalid memory address or an unsupported value. Also what an ECU answers when a DID exists but not in this session, so it is useful for mapping.
0x33securityAccessDeniedThe ECU is locked. The service or data needs a successful SecurityAccess (0x27) first. For a tester, this marks the protected surface.
0x34authenticationRequiredThe service needs a successful Authentication (0x29) first.
0x35invalidKeyThe key sent for SecurityAccess did not match the seed. Count these: a weak implementation does not limit attempts.
0x36exceedNumberOfAttemptsToo many wrong keys; the ECU has locked SecurityAccess for a while. This is the correct behaviour.
0x37requiredTimeDelayNotExpiredThe delay after a failed attempt or after power-up has not expired yet.
0x38secureDataTransmissionRequiredThe request must be sent through SecuredDataTransmission (0x84).
0x39secureDataTransmissionNotAllowedThis request must not be sent through SecuredDataTransmission.
0x3AsecureDataVerificationFailedVerification of a secured data transmission failed.
0x50certificateVerificationFailedInvalidTimePeriodAuthentication (0x29): certificate not valid at this time.
0x51certificateVerificationFailedInvalidSignatureAuthentication (0x29): certificate signature invalid.
0x52certificateVerificationFailedInvalidChainOfTrustAuthentication (0x29): certificate chain not trusted.
0x53certificateVerificationFailedInvalidTypeAuthentication (0x29): wrong certificate type.
0x54certificateVerificationFailedInvalidFormatAuthentication (0x29): certificate format invalid.
0x55certificateVerificationFailedInvalidContentAuthentication (0x29): certificate content invalid.
0x56certificateVerificationFailedInvalidScopeAuthentication (0x29): certificate scope does not cover this.
0x57certificateVerificationFailedInvalidCertificateAuthentication (0x29): certificate revoked or otherwise invalid.
0x58ownershipVerificationFailedAuthentication (0x29): proof of ownership failed.
0x59challengeCalculationFailedAuthentication (0x29): the ECU could not calculate the challenge.
0x5AsettingAccessRightsFailedAuthentication (0x29): access rights could not be set.
0x5BsessionKeyCreationOrDerivationFailedAuthentication (0x29): session key derivation failed.
0x5CconfigurationDataUsageFailedAuthentication (0x29): configuration data could not be used.
0x5DdeAuthenticationFailedAuthentication (0x29): de-authentication failed.
0x70uploadDownloadNotAcceptedRequestDownload or RequestUpload refused: wrong address, length, format or state.
0x71transferDataSuspendedThe data transfer was suspended by the ECU.
0x72generalProgrammingFailureWriting to memory failed during programming.
0x73wrongBlockSequenceCounterTransferData block counter out of sequence.
0x78requestCorrectlyReceived-ResponsePendingNot an error: the ECU needs more time and will send the final response later. The tester extends its P2* timeout. Watch for ECUs that never follow up.
0x7EsubFunctionNotSupportedInActiveSessionThe sub-function exists but not in the current session. Switch session (0x10) and try again.
0x7FserviceNotSupportedInActiveSessionThe service exists but not in the current session. Classic marker for services that live in extended or programming session.
0x81rpmTooHighEngine speed too high for this action.
0x82rpmTooLowEngine speed too low for this action.
0x83engineIsRunningNot allowed while the engine runs.
0x84engineIsNotRunningOnly allowed while the engine runs.
0x85engineRunTimeTooLowEngine has not run long enough.
0x86temperatureTooHighTemperature too high for this action.
0x87temperatureTooLowTemperature too low for this action.
0x88vehicleSpeedTooHighVehicle speed too high for this action. The usual guard on actuator tests.
0x89vehicleSpeedTooLowVehicle speed too low for this action.
0x8Athrottle/PedalTooHighThrottle or pedal position too high.
0x8Bthrottle/PedalTooLowThrottle or pedal position too low.
0x8CtransmissionRangeNotInNeutralTransmission must be in neutral.
0x8DtransmissionRangeNotInGearTransmission must be in gear.
0x8FbrakeSwitch(es)NotClosedBrake pedal must be pressed.
0x90shifterLeverNotInParkShift lever must be in park.
0x91torqueConverterClutchLockedTorque converter clutch is locked.
0x92voltageTooHighSupply voltage too high, often during programming.
0x93voltageTooLowSupply voltage too low, often during programming.
0x94resourceTemporarilyNotAvailableA needed resource is busy; try again later.

How it works

A UDS negative response is always three bytes: 7F, the service identifier (SID) of the rejected request, and the negative response code. The tool accepts the full response or just the code, looks it up in the ISO 14229-1 table and adds what the code usually tells you when you test an ECU, written from the tester’s point of view rather than the ECU’s.

The table covers all codes defined in ISO 14229-1:2020 Annex A, including the range 0x50 to 0x5D used by the Authentication service (0x29) and the vehicle-condition codes 0x81 to 0x94. Codes outside the table are manufacturer-specific or reserved.

How to read the result

Three codes carry most of the information during enumeration. 0x11 serviceNotSupported means the service does not exist on this ECU at all. 0x7F serviceNotSupportedInActiveSession means it exists but needs another session, typically extended (0x03) or programming (0x02). 0x33 securityAccessDenied marks the surface that is protected by SecurityAccess. An ECU that answers 0x12 or 0x7E for sub-functions, and 0x31 for unknown identifiers, is telling you its map one response at a time.

During SecurityAccess testing, count 0x35 invalidKey responses. After the configured number of attempts the ECU must answer 0x36 exceedNumberOfAttempts and then 0x37 requiredTimeDelayNotExpired. An ECU that keeps answering 0x35 has no attempt counter, which is a finding.

Limits

The tool knows the standard codes, not what your ECU does with them. Some implementations answer 0x10 generalReject to everything they do not understand, which hides the structure. Some mislabel conditions. AutoST’s enumeration treats the responses statistically across sessions, which is how it maps services and identifiers even on such ECUs.

FAQ

Frequently asked questions

What is the structure of a UDS negative response?

Three bytes: 0x7F, the service identifier of the request that was rejected, and the negative response code. A tester that sends 27 03 (SecurityAccess, requestSeed level 3) and receives 7F 27 7E learns that sub-function 03 exists but not in the active session.

Is 0x78 an error?

No. requestCorrectlyReceived-ResponsePending tells the tester the ECU needs more time; the tester extends its P2* timeout and waits for the final response. ECUs that send 0x78 and then never answer are a finding, because the tester hangs.

Why do some ECUs answer 0x31 instead of 0x7F for unknown DIDs?

requestOutOfRange (0x31) is the correct answer to a DID the ECU does not support, while serviceNotSupportedInActiveSession (0x7F) means the whole service is unavailable in the current session. Mixing them up is common and makes enumeration harder; AutoST interprets both.

Sources

Related pages

See it on your ECU

Useful? The full suite does this against your ECU, automatically.

In a one-hour demo we run AutoST against a demo ECU or, if you have one on the bench, against yours.

  • Enumeration, SecurityAccess, fuzzing, DoIP live
  • Your questions answered by an engineer
  • Free and without obligation
Tom Zaubermann

Your demo is withTom ZaubermannFounder of Zyberum, ex-lead of the VW InCar Security Testing Lab

Already trusted by Tier 1, Tier 2 suppliers and OEMs. References on request.

Call us: +49 176 439 17074automotive@zyberum.com

Or send us a message

We reply within one business day.

Call usSee the full test suite

Pick a time that suits you

Open in a new tab