CVE-2024-58330
Received Received - Intake

Authentication Bypass in Bosch IP Cameras

Vulnerability report for CVE-2024-58330, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: Robert Bosch GmbH

Description

A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-23
AI Q&A
2026-07-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
bosch ip_cameras cpp13
bosch ip_cameras cpp14

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.

Detection Guidance

To detect this vulnerability, check Bosch IP cameras in the CPP13 and CPP14 families for unauthorized access to video analytics event data. Monitor network traffic for unauthenticated requests to camera endpoints. Use tools like Wireshark to inspect HTTP/HTTPS traffic for unusual requests targeting camera APIs.

Impact Analysis

An attacker could access sensitive video analytics event data without authentication, potentially exposing private or confidential information captured by the cameras.

Compliance Impact

The vulnerability allows unauthenticated access to video analytics event data, which could expose sensitive information. This may violate GDPR if personal data is involved, as unauthorized access breaches data protection principles. For HIPAA, if the cameras process protected health information, the lack of authentication could lead to unauthorized disclosure, violating security requirements.

Mitigation Strategies

Update Bosch IP cameras of families CPP13 and CPP14 to the latest firmware version to address the missing authentication check. Ensure network segmentation to restrict access to the cameras from untrusted networks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-58330. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart