A single unsigned SAML GET can forge a NetScaler Gateway or AAA session.
The affected Redirect-binding path defeats the default unsigned-assertion policy.
Customer-managed NetScaler ADC and NetScaler Gateway appliances exposing SAML-authenticated Gateway or AAA virtual servers.
Unauthenticated session forgery on a SAML-configured NetScaler Gateway or AAA virtual server
This is a code-backed authentication bypass: a reachable SAML endpoint can construct a session from attacker-controlled assertion fields without a signed assertion.
Detail, proof-of-concept code and 4 sources
The caller collects the pre-authentication redirect values, sends an attacker-built unsigned assertion to /cgi/samlauth, and receives a session after the parser clears strict signature enforcement.
Public code performs the forgery. Citrix has fixed builds, but pre-fix images remain accepted; matching probes do not yet establish successful compromise.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
The fixed implementation is proprietary and no fixed-binary diff establishing broader legacy coverage was available; definite conclusions are therefore limited to the documented downgrade behavior.