Skip to main content
Datagram Transport Layer Security

Datagram Transport Layer Security

Internet protocolWikipedia

Search complete. 40 mentions across 17 episodes found for "Datagram Transport Layer Security".

Oct 9, 2026

Ingela AndinGUEST
17:16
So, uh, so that you could, like, have a malicious server fool the client.
Ingela AndinGUEST
17:21
And some of them are against the DTLS, which in short is, uh, TLS over UDP, and that means that application data may be lost.
Ingela AndinGUEST
17:32
Um, and, uh, this is a requirement area where we put less effort.
Ingela AndinGUEST
17:39
It was, uh, somebody that, uh, wanted it, but then they dropped requirement.
Herman PoppleberryHOST
5:35
The manager receives traps and informs on port 162.
Herman PoppleberryHOST
5:39
And with TLS or DTLS wrapping it, ports 161 and W62.
CornHOST
5:45
Why UDP? That's a real choice.
Herman PoppleberryHOST
5:48
Because it's cheap.
Martin ReynoldsHOST
0:50
So the first is an, uh, an authenticated, uh, RCE flaw, uh, that hits nearly every version of NetScaler, even default deployments.
Martin ReynoldsHOST
1:01
And the second is a memory overflow that also leads to RCE, and DTLS is on default on VPN, uh, virtual servers.
Martin ReynoldsHOST
1:10
So almost all of them are in scope.
Starr BrownGUEST
1:13
Yeah.
Marc LaliberteHOST
5:46
Never forget.
Marc LaliberteHOST
5:48
So anyways, the vulnerability itself takes place in how the Citrix NetScaler appliance handles DTLS fragmentation.
Marc LaliberteHOST
5:56
So DTLS, it's the way to add encryption to UDP packets.
Marc LaliberteHOST
6:01
There's a bit of a handshake that's kind of different than how you would do it over a TCP-based connection.
Marc LaliberteHOST
6:07
But it supports fragmenting packets, meaning you can send a larger piece of data over multiple smaller packets.
Paul AsadoorianHOST
45:10
We can hit these really quick.
Paul AsadoorianHOST
45:12
Watchtower analyzed that pre-auth DTLS memory overflow.
Paul AsadoorianHOST
45:17
Turns out DTLS is TLS over UDP.
Paul AsadoorianHOST
45:20
Weird.
Paul AsadoorianHOST
45:21
Okay.

7 MINS LATER

Paul AsadoorianHOST
52:20
So like if you're running that version, you're vulnerable.
Paul AsadoorianHOST
52:23
And the rest of them require that a feature be enabled.
Paul AsadoorianHOST
52:26
The DTLS is actually enabled if you're using the VPN functionality on it.
Paul AsadoorianHOST
45:10
We can hit these really quick.
Paul AsadoorianHOST
45:12
Watchtower analyzed that pre-auth DTLS memory overflow.
Paul AsadoorianHOST
45:17
Turns out DTLS is TLS over UDP.
Paul AsadoorianHOST
45:20
Weird.
Paul AsadoorianHOST
45:21
Okay.

7 MINS LATER

Paul AsadoorianHOST
52:20
So like if you're running that version, you're vulnerable.
Paul AsadoorianHOST
52:23
And the rest of them require that a feature be enabled.
Paul AsadoorianHOST
52:26
The DTLS is actually enabled if you're using the VPN functionality on it.
Paul AsadoorianHOST
45:10
We can hit these really quick.
Paul AsadoorianHOST
45:12
Watchtower analyzed that pre-auth DTLS memory overflow.
Paul AsadoorianHOST
45:17
Turns out DTLS is TLS over UDP.
Paul AsadoorianHOST
45:20
Weird.
Paul AsadoorianHOST
45:21
Okay.

7 MINS LATER

Paul AsadoorianHOST
52:20
So like if you're running that version, you're vulnerable.
Paul AsadoorianHOST
52:23
And the rest of them require that a feature be enabled.
Paul AsadoorianHOST
52:26
The DTLS is actually enabled if you're using the VPN functionality on it.
speaker_0HOST
0:59
It fires during the first handshake before any login and hands over route.
speaker_0HOST
1:03
DTLS is on by default for gateway VPNs, so patch now and hunt for the Blipshot and Sloughchip web shells.
speaker_0HOST
1:10
Two flaws in Amazon Bedrock Agent Core's Python kit led a crafted package named smuggle-shell-commands into its code interpreter sandbox, exposing the sandbox's temporary AWS credentials.
speaker_0HOST
1:21
The awkward part? AWS's first fix was bypassed too.
speaker_0HOST
2:45
This is the engine that handles incoming data.
speaker_0HOST
2:48
And specifically, they're exploiting how this engine parses the Datagram Transport Layer Security Protocol or DTLS.
speaker_1HOST
2:56
DTLS, right, which is heavily used for streaming and VPN connections, I think.
speaker_0HOST
3:00
Exactly, because it relies on UDP.
speaker_0HOST
3:03
So it doesn't require that strict back and forth acknowledgement that a standard TCP connection does.
speaker_0HOST
3:09
It's built for speed.
speaker_1HOST
3:10
OK, so the engine is expecting this really fast streaming DTLS traffic.
speaker_1HOST
3:14
How do the attackers break it?
speaker_0NARRATOR
0:19
One weakness allows unauthenticated code execution in default deployments.
speaker_0NARRATOR
0:24
The other affects systems with DTLS enabled.
speaker_0NARRATOR
0:28
CISA added both to its known exploited vulnerabilities catalog, and more than 20,000 internet-exposed instances were reported as potentially at risk.
speaker_0NARRATOR
0:39
Confirmed compromises were not described as widespread.

7 more episodes mention Datagram Transport Layer Security.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.