Sceawere

Vulnerability Detail

CVE-2024-58330Updated Verified Sceawere Triage Sources: NVD / CISA KEV

Bosch IP Camera Authentication Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
2h ago
Vendor
Bosch
Product
Camera Firmware
Attack Type
CWE-284 Improper Access Control
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-07-23T09:16:26.430Z",
  "pubdate": "2026-07-23T09:16:26.430Z",
  "executiveSummary": "A missing authentication check vulnerability exists in Bosch IP cameras utilizing the CPP13 and CPP14 device families.\nThe vulnerability allows an unauthenticated, remote attacker to bypass access controls and retrieve sensitive video analytics event data directly from the affected camera systems.\nThe flaw stems from an inadequate authorization verification mechanism within the endpoint responsible for handling video analytics events.\nSuccessful exploitation exposes sensitive operational and surveillance data without requiring user interaction, valid credentials, or elevated privileges.\nThe risk implication is unauthorized information disclosure, potentially compromising physical security intelligence and surveillance privacy.\nRemediation requires applying official firmware updates provided by the vendor when available, restricting network exposure, and implementing strict perimeter network segmentation.",
  "technicalDetails": "The vulnerability is classified as a missing authentication check, where critical functional endpoints fail to validate the identity and authorization state of incoming requests.\nThe affected components reside within Bosch IP cameras belonging to the CPP13 and CPP14 product families, specifically within the subsystem handling video analytics event processing and retrieval.\nThe root cause is an improper access control implementation in the request handling routine, allowing HTTP or network requests destined for video analytics data to bypass security validation checks entirely.\nAn unauthenticated attacker positioned on the network can exploit this vulnerability by sending crafted requests directly to the vulnerable service endpoint.\nThe attack flow proceeds as follows: First, the attacker identifies a target Bosch IP camera running vulnerable CPP13 or CPP14 firmware exposed to the network. Second, the attacker formulates a network request targeting the video analytics event retrieval interface without supplying valid authentication headers or session tokens. Third, because the underlying application logic fails to enforce authentication checks, the component processes the request and responds with the requested video analytics event data. Finally, the attacker receives and parses the data, gaining unauthorized visibility into system events and surveillance metadata.\nThe vulnerability requires network connectivity to the target camera, typically over local network segments or via improper wide area network exposures, but requires zero privileges or user interaction for successful execution.\nPost-exploitation impact is limited to unauthorized information disclosure of video analytics telemetry, but this data may reveal sensitive operational patterns, movement tracking, and environmental metadata captured by the surveillance device."
}
CVE-2024-58330: Bosch IP Camera Authentication Bypass (HIGH Severity, CVSS: 7.5) - Sceawere