CVE-2023-42670 is a medium-severity flaw in Samba, specifically affecting Fedora and Samba products, where incompatible RPC listeners can be initiated, disrupting Active Directory Domain Controller (AD DC) services. This vulnerability, with a CVSS score of 6.5, allows an authenticated attacker to cause a denial of service by triggering partial query responses and errors like "The procedure number is out of range." There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Despite limited community discussion and media coverage, the potential for service disruption warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.17.12CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.18.0, < 4.18.8CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
>= 4.19.0, < 4.19.1CPE matchmatch criteria | cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.