logo

Database

Aws Unencrypted Snapshots

Description

Detects AWS EC2 snapshots that are not encrypted. EBS snapshots store point-in-time copies of EBS volumes and may contain sensitive data, making encryption critical for data protection. Unencrypted snapshots could expose sensitive data if unauthorized access occurs.

Weakness:

333 - Insecure service configuration - EC2

Category: Functionality Abuse

Detection Strategy

    Retrieves all EBS snapshots owned by the current AWS account

    Checks each snapshot's 'Encrypted' property to determine if encryption is enabled

    Reports a vulnerability when a snapshot's 'Encrypted' property is set to false

    Captures the snapshot ID and region in the vulnerability report for remediation

Severity v4.0

2.1

Low

Method ID

CSPM-3ESTU

Technique

CSPM

Target

AWS

Technology

EC2

CWE ID(s)

CWE-497