Impact
A missing authentication check in the analytic data endpoint of Bosch IP cameras (families CPP13 and CPP14) allows any network actor to retrieve video analytics event data. The flaw is an improper access control defect (CWE‑284) that facilitates unauthenticated data exfiltration.
Affected Systems
Bosch Camera Firmware for the CPP13 and CPP14 product families. No specific firmware revisions are identified, so all firmware versions for these families should be considered vulnerable until a patched version is released.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating high severity. The EPSS score is less than 1 %, suggesting that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network access to the camera’s analytics endpoint, where the missing authentication check permits unauthenticated retrieval of logs without requiring privileged credentials.
OpenCVE Enrichment