Aws Instance Tls Disabled
Description
Detects AWS RDS database instances that do not enforce TLS/SSL encrypted connections from clients. When TLS is not enforced, sensitive data transmitted between clients and the database could be exposed to network-level attacks.
Detection Strategy
• Examines each RDS instance's parameter group settings
• Checks if 'require_secure_transport' or 'rds.force_ssl' parameters are set to '0' or 'OFF'
• Reports a vulnerability if SSL/TLS encryption is not mandatory for client connections to the database
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan.If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.