Citrix NetScaler reboots after patching CVE-2023-4966 and CVE-2023-4967
Key Takeaways Citrix NetScaler appliances are experiencing unexpected reboots after applying emergency patches for two critical zero-day vulnerabilities (CVE-2023-4966 and CVE-2023-4967). The reboots...
Key Takeaways
- Citrix NetScaler appliances are experiencing unexpected reboots after applying emergency patches for two critical zero-day vulnerabilities (CVE-2023-4966 and CVE-2023-4967).
- The reboots appear to be triggered by specially crafted SAML authentication traffic, causing the
nsaaadservice to crash, leading to a denial-of-service condition. - While the September patch (build 14.1-73.37) is believed to address the original zero-day flaws, the new reboot issue represents a separate, ongoing problem.
- Citrix is actively investigating this new SAML-related issue and plans to release further guidance and a new fixed build.
Customers utilizing Citrix NetScaler appliances are encountering an alarming issue: repeated reboots following the installation of build 14.1-73.37. This emergency update was released to mitigate two actively exploited zero-day vulnerabilities, CVE-2023-4966 and CVE-2023-4967.
Table Of Content
The reported system failures seem to stem from malformed SAML authentication requests, which are causing the nsaaad service to crash. Citrix has acknowledged the emergence of this new SAML-related problem, confirming that its engineering and support teams are investigating and intend to issue an updated security bulletin along with a new patched build.
It is crucial to emphasize that these reboot incidents do not, at this stage, indicate a bypass of the September patch. Build 14.1-73.37 remains the official fix for the original vulnerabilities. The first flaw, CVE-2023-4966, allowed unauthenticated attackers to execute commands on affected deployments. The second, CVE-2023-4967, could lead to code execution or denial of service if DTLS was enabled. Citrix had previously confirmed active exploitation against unpatched systems.
Why Patched Systems Reboot
Administrators have taken to Reddit to describe external NetScaler appliances running the 14.1-73.37 build entering unexpected reboot cycles. One administrator reported that several clients were affected, leading to critical severity-one support cases with Citrix.
Another report detailed how vulnerability scans were followed by repeated crashes of the nsaaad process. After a certain number of failures, the pitboss watchdog mechanism would initiate an appliance restart. While Citrix support is reportedly preparing a fix, these claims from forum discussions have not yet been formally confirmed in a final vendor bulletin.
The nature of this pattern is significant because the nsaaad service is responsible for handling authentication tasks. A specially crafted request could crash this process, resulting in a denial-of-service event without necessarily granting the attacker control over the device. However, repeated crashes can still severely disrupt services, particularly for internet-facing gateways vital for remote access. High-availability configurations could also be impacted if both nodes receive the malicious traffic or reboot sequentially.
Citrix’s interim SAML deployment guidance advises customers to verify their configurations, review available mitigation options, and prepare for the next fixed build. As of this writing, the notice does not include a new CVE identification, comprehensive root-cause analysis, or a definitive release number for the upcoming fix. This means security teams should avoid misinterpreting every reboot as a confirmed breach or assuming that the 14.1-73.37 patch has re-introduced the previously addressed vulnerabilities.
What You Should Do
- Before any further reboots, preserve forensic evidence by collecting core files, system logs, authentication records, and a support bundle.
- Correlate reboot timestamps with inbound SAML requests, firewall logs, and identity provider records.
- Investigate
nsaaadcrash messages, examine files in/var/core, review recent configuration changes, look for unknown administrator sessions, and monitor for unusual outbound traffic. - Treat any temporary blocking rules as short-term measures, as attacker source addresses can change.
- Confirm the installed build on all active and standby nodes. Citrix’s CTX697096 bulletin lists 14.1-73.37, 13.1-64.23, and corresponding FIPS or NDcPP releases as the definitive fixes for the original zero-days.
- Remember that applying the patch prevents new exploitation of the original flaws but does not remove any existing web shells or unauthorized access gained prior to the update.
- Keep severity-one support cases open with Citrix, adhere strictly to vendor-provided mitigation steps, and treat any unexplained reboots as both an operational disruption and a potential security incident.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.