Impact
Cleartext transmission of operator control commands to robot UDP traffic allows an unauthenticated attacker to intercept, hijack, or modify control traffic. The lack of a cryptographic integrity check means that commands can be altered or replayed without detection, potentially causing the robot to perform unintended actions or be disabled.
Affected Systems
Teledyne FLIR Aware2 software, including PackBot (versions up to 6.9.0.2) and FirstLook (versions up to 1.7.9), is affected.
Risk and Exploitability
The vulnerability has a CVSS score of 8.5, indicating a high severity level. EPSS data is not available, but the ability to modify control traffic over an adjacent network suggests a relatively straightforward local attack. The issue is not listed in CISA's KEV catalog yet, but the impact on robot safety and mission integrity means it should be treated with urgency.
OpenCVE Enrichment