now there’s this (https://bishopfox.com/blog/citrix-adc-gateway-rce-cve-2023-3519) too, which suggests that the SAML thing is something else that got patched, because they exploited something they think is cve-2023-3519 without needing SAML enabled at all.
If this is a buffer overflow in SAML, wouldn’t you essentially need to be the IDP to pull this off? How else are you able to send SAML Assertions that the netscaler wouldn’t otherwise drop?
Quick Cookie Notification
This site uses cookies for anonymized analytics to improve the site.
Rapid7 will never sell the data collected on this site.
now there’s this (https://bishopfox.com/blog/citrix-adc-gateway-rce-cve-2023-3519) too, which suggests that the SAML thing is something else that got patched, because they exploited something they think is cve-2023-3519 without needing SAML enabled at all.