Sceawere
Vulnerability Detail
CVE-2024-58330Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Bosch IP Camera Authentication Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 2h ago
- Vendor
- Bosch
- Product
- Camera Firmware
- Attack Type
- CWE-284 Improper Access Control
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-07-23T09:16:26.430Z",
"pubdate": "2026-07-23T09:16:26.430Z",
"executiveSummary": "A missing authentication check vulnerability exists in Bosch IP cameras utilizing the CPP13 and CPP14 device families.\nThe vulnerability allows an unauthenticated, remote attacker to bypass access controls and retrieve sensitive video analytics event data directly from the affected camera systems.\nThe flaw stems from an inadequate authorization verification mechanism within the endpoint responsible for handling video analytics events.\nSuccessful exploitation exposes sensitive operational and surveillance data without requiring user interaction, valid credentials, or elevated privileges.\nThe risk implication is unauthorized information disclosure, potentially compromising physical security intelligence and surveillance privacy.\nRemediation requires applying official firmware updates provided by the vendor when available, restricting network exposure, and implementing strict perimeter network segmentation.",
"technicalDetails": "The vulnerability is classified as a missing authentication check, where critical functional endpoints fail to validate the identity and authorization state of incoming requests.\nThe affected components reside within Bosch IP cameras belonging to the CPP13 and CPP14 product families, specifically within the subsystem handling video analytics event processing and retrieval.\nThe root cause is an improper access control implementation in the request handling routine, allowing HTTP or network requests destined for video analytics data to bypass security validation checks entirely.\nAn unauthenticated attacker positioned on the network can exploit this vulnerability by sending crafted requests directly to the vulnerable service endpoint.\nThe attack flow proceeds as follows: First, the attacker identifies a target Bosch IP camera running vulnerable CPP13 or CPP14 firmware exposed to the network. Second, the attacker formulates a network request targeting the video analytics event retrieval interface without supplying valid authentication headers or session tokens. Third, because the underlying application logic fails to enforce authentication checks, the component processes the request and responds with the requested video analytics event data. Finally, the attacker receives and parses the data, gaining unauthorized visibility into system events and surveillance metadata.\nThe vulnerability requires network connectivity to the target camera, typically over local network segments or via improper wide area network exposures, but requires zero privileges or user interaction for successful execution.\nPost-exploitation impact is limited to unauthorized information disclosure of video analytics telemetry, but this data may reveal sensitive operational patterns, movement tracking, and environmental metadata captured by the surveillance device."
}