Citrix released new CVE bullettin.
Affected Netscaler versions are:
- NetScaler ADC and NetScaler Gateway 14.1-73.41 and later releases
- NetScaler ADC and NetScaler Gateway 13.1-64.28 and later releases of 13.1
- NetScaler ADC 14.1-FIPS 14.1-73.41 FIPS and later releases of 14.1-FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.282 and later releases of 13.1-FIPS and 13.1-NDcPP
Citrix article explain how to determine if an appliance meets the CVE preconditions.
Meanwhile I share steps to be done on Netscaler:
a) Connect though SSH to search if saml is configured using these commands:
show ns runningConfig | grep -i saml
show authentication samlAction
show authentication samlIdPProfile
b) Though GUI:
- Log in on Netscaler
- Configuration search for --> saml
- Configuration --> Security ---> AAA-Application Traffic --> Policies --> Authentication