CVE-2026-14984
Received
Received - Intake
Cleartext Transmission in Teledyne FLIR Aware2
Vulnerability report for CVE-2026-14984, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-01
Last updated on: 2026-10-01
Assigner: Mandiant Inc.
Description
Description
Cleartext transmission in the primary control endpoints of Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| teledyne_flir | aware2 | to 6.9.0.2 (inc) |
| teledyne_flir | packbot | * |
| teledyne | flir_aware2 | to 6.9.0.2 (inc) |
| teledyne | packbot | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-319 | The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. |