Description
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.
Published: 2026-07-23
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authentication check in the analytic data endpoint of Bosch IP cameras (families CPP13 and CPP14) allows any network actor to retrieve video analytics event data. The flaw is an improper access control defect (CWE‑284) that facilitates unauthenticated data exfiltration.

Affected Systems

Bosch Camera Firmware for the CPP13 and CPP14 product families. No specific firmware revisions are identified, so all firmware versions for these families should be considered vulnerable until a patched version is released.

Risk and Exploitability

The vulnerability has a CVSS score of 7.5, indicating high severity. The EPSS score is less than 1 %, suggesting that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network access to the camera’s analytics endpoint, where the missing authentication check permits unauthenticated retrieval of logs without requiring privileged credentials.

Generated by OpenCVE AI on August 5, 2026 at 01:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Bosch IP camera firmware to the latest version that addresses the missing authentication check, following the Bosch PSIRT advisory at https://psirt.bosch.com/security-advisories/BOSCH-SA-659648.html.
  • Restrict network exposure of the cameras by applying firewall rules, VLAN segmentation, or disabling remote interfaces so that only trusted internal networks can reach the analytics endpoint.
  • Disable or lock down any APIs or endpoints that expose video analytics event data until proper authentication checks are implemented.
  • Monitor camera event logs for unauthorized access attempts and investigate any anomalies promptly.

Generated by OpenCVE AI on August 5, 2026 at 01:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Bosch IP Cameras Missing Authentication in Video Analytics Endpoint

Sat, 01 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Retrieval of Video Analytics Event Data in Bosch IP Cameras

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Bosch
Bosch camera Firmware
Vendors & Products Bosch
Bosch camera Firmware

Sun, 26 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Retrieval of Video Analytics Event Data in Bosch IP Cameras

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Bosch Camera Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: bosch

Published:

Updated: 2026-07-23T13:59:27.140Z

Reserved: 2026-07-23T07:45:15.716Z

Link: CVE-2024-58330

cve-icon Vulnrichment

Updated: 2026-07-23T13:59:24.134Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-23T09:16:26.430

Modified: 2026-07-23T15:48:25.133

Link: CVE-2024-58330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:15:03Z

Weaknesses