CVE-2021-32634 is an Unsafe Deserialization vulnerability affecting Emissary versions up to 6.4.0, a distributed workflow framework developed by the NSA. This flaw allows post-authenticated attackers to achieve Remote Code Execution via the WorkSpaceClientEnqueue.action REST endpoint. With a CVSS score of 7.2 (HIGH), exploitation is network-based and low complexity, leading to high impact on confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the vulnerability has been patched in Emissary 6.5.0, and disabling network access from untrusted sources serves as a workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.4.0CPE matchmatch criteria | cpe:2.3:a:nsa:emissary:6.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.