CVE-2026-14984 PUBLISHED

Cleartext HTTP for Control Traffic in Teledyne FLIR Robots running Aware2

Assigner: Mandiant
Reserved: 07.07.2026 Published: 01.10.2026 Updated: 01.10.2026

Cleartext transmission in the primary control endpoints of Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.4

Product Status

Vendor Teledyne FLIR
Product Aware2
Versions Default: unaffected
  • affected from 0 to 6.9.0.2 (incl.)

References

Problem Types

  • CWE-319: Cleartext Transmission of Sensitive Information CWE

Impacts

  • CAPEC-158: Sniffing Network Traffic