CVE-2022-38734
published 2023-03-02CVE-2022-38734: StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.62%
45.3th percentile
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to to a crash of the Local Distribution Router (LDR) service.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netapp | storagegrid | < 11.6.0.8 | 11.6.0.8 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NetApp StorageGRID up to 11.6.0 Local Distribution Router denial of service (ntap-20230228-0001 / EUVD-2022-41301)
vuldb·2026-06-24·CVSS 7.5
CVE-2022-38734 [HIGH] NetApp StorageGRID up to 11.6.0 Local Distribution Router denial of service (ntap-20230228-0001 / EUVD-2022-41301)
A vulnerability was found in NetApp StorageGRID up to 11.6.0. It has been classified as problematic. Impacted is an unknown function of the component Local Distribution Router. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2022-38734. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is recommended.
GHSA
GHSA-3xqx-95w6-xjv4: StorageGRID (formerly StorageGRID Webscale) versions prior to 11
ghsa_unreviewed·2023-03-02
CVE-2022-38734 [HIGH] CWE-400 GHSA-3xqx-95w6-xjv4: StorageGRID (formerly StorageGRID Webscale) versions prior to 11
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to to a crash of the Local Distribution Router (LDR) service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-02
Published