A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2024-58330 is a missing authentication vulnerability affecting Bosch CPP13 and CPP14 IP camera families that allows unauthenticated attackers to access video analytics event data. This represents a significant security gap because video analytics events often contain sensitive information about facility activity, occupancy patterns, and security-relevant detections. Organizations deploying these camera models for surveillance, access control monitoring, or perimeter security face immediate exposure of surveillance intelligence without any credential requirement. The vulnerability is particularly dangerous in enterprise environments where camera networks are assumed to be protected by authentication controls, potentially affecting healthcare facilities, corporate offices, government buildings, and critical infrastructure sites.
While CVE-2024-58330 is not yet mapped to specific MITRE ATT&CK techniques, Casky's security skills enable detection of the underlying attack patterns through reconnaissance and credential-less access attempts. Practitioners using Casky would observe findings related to CWE-284 (Improper Access Control) patterns—specifically monitoring for unauthenticated API requests to camera endpoints, unusual data retrieval from /api/analytics or similar event endpoints without authentication tokens, and anomalous queries for video metadata and event logs from external sources. Claude's extended reasoning capabilities help practitioners correlate these suspicious patterns with camera firmware versions and IP ranges, identifying which devices are vulnerable while distinguishing legitimate camera queries from reconnaissance activity targeting surveillance infrastructure. The absence of required authentication tokens in HTTP requests to analytics endpoints would be flagged as a critical control gap requiring immediate firmware patching or network segmentation.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2024-58330. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation