Impact
A flaw in StorageGRID (formerly StorageGRID Webscale) versions 11.5 and above in a non‑standard configuration can let an attacker trigger a Partial Denial of Service. The vulnerability derives from improper handling of resource initialization, which falls under CWE‑774. Attackers could overwhelm critical services, causing them to become unresponsive or completely unavailable to legitimate users.
Affected Systems
The affected product is NetApp StorageGRID. Versions 11.5 and higher running in non‑standard deployment scenarios are impacted. The problem is not tied to a specific patch level beyond the version threshold; any installation of 11.5 or newer in a non‑standard configuration is at risk.
Risk and Exploitability
The CVSS score is 2.3, indicating a low severity for this denial of service. The EPSS score is not available, so the current estimate of exploitation likelihood is unclear. This vulnerability is not listed in CISA KEV. The likely attack vector requires the attacker to have some control over the environment – for example, the ability to add custom configuration or alter deployment parameters – rather than remote exploitation over the network.
OpenCVE Enrichment