Emergency Security Bulletin: Insufficient Input Validation in NetScaler SAML Authentication

https://www.redlegg.com/hubfs/Theme-2024/overlay-red.png featured image

By: RedLegg's Cyber Threat Intelligence Team

About:

A newly disclosed NetScaler SAML authentication vulnerability affects customer-managed NetScaler ADC and Gateway deployments configured for SAML authentication. While Citrix has not yet released fixed builds, the flaw impacts internet-facing authentication workflows that may be reachable before user authentication occurs. Organizations should immediately identify affected appliances, validate SAML usage, and prepare to deploy vendor updates as soon as they become available.

RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.


VULNERABILITIES

Insufficient Input Validation in NetScaler SAML Authentication

 

Update / Patch:
No fixed builds are currently available. Citrix states a simultaneous security bulletin and fixed build release is forthcoming. Apply fixed builds immediately upon release.

Affected versions include:
Configuration-dependent. No specific version ranges are available at this time. Any NetScaler ADC or Gateway with add authentication samlAction.* or add authentication samlIdPProfile.* in the running configuration is in scope.

Fixed versions include:
Pending bulletin publication.

NetScaler advisory and patch guidance:
https://community.citrix.com/techzone-blogs/110_security-updates/security-update-guidance-for-netscaler-saml-authentication-deployments

Description:
The vulnerability affects customer-managed NetScaler ADC and NetScaler Gateway deployments with SAML authentication configured. At least one of two directives must be present in the running configuration: samlAction (SAML Service Provider role) or samlIdPProfile (SAML Identity Provider role).

SAML authentication endpoints on NetScaler are reachable before authentication completes. A vulnerability in that processing chain typically requires no valid credentials from the attacker. NetScaler appliances in Gateway or AAA configurations expose these endpoints at the network edge.

Mitigation Recommendation:
Audit all customer-managed NetScaler appliances now. Run the following from the CLI as nsroot:
show authentication samlAction
show authentication samlIdPProfile

Or check the configuration file directly:
grep -iE "add authentication saml(Action|IdPProfile)" /nsconfig/ns.conf

Any output means the appliance is in scope. Prioritize internet-facing Gateway and AAA virtual servers. Confirm binding to an active virtual server with show vpn vserver and show authentication vserver.

If SAML is not operationally required on a given appliance, evaluate temporarily disabling the SAML authentication action pending fixed build availability.

Apply fixed builds immediately when Citrix publishes the security bulletin.

Restrict NSIP access to trusted IP ranges if not already enforced.

Forward NetScaler authentication logs to your SIEM. Monitor for malformed SAML request patterns at /saml/login and /wsfed/passive, unexpected authentication errors, and unusual process or file activity on the appliance.

If post-exploitation indicators are found, initiate Incident Response immediately.