Science & Tech · Cybersecurity · 2 days ago

Citrix patches critical NetScaler flaw affecting some SAML deployments

Citrix patches critical NetScaler flaw affecting some SAML deployments

Citrix has released security updates for a critical flaw in its NetScaler ADC and NetScaler Gateway products.

The memory-overflow flaw could let an attacker run code remotely or disrupt services under certain conditions.

It affects deployments configured as a SAML identity provider or service provider, which customers can check in their device settings.

Citrix rates the vulnerability 9.5 out of 10 for severity.

Citrix says it is not aware of attacks exploiting this particular flaw.

The company recommends that affected customers upgrade to the patched versions, including NetScaler 14.1-73.46 or later and 13.1-64.29 or later, with separate updates for FIPS versions.

Some versions and configurations differ in which systems are affected, so customers should check Citrix’s advisory before upgrading.

Sources

Related news