logo

Database

Aws Virtual Gateway Tls Disabled

Description

Identifies AWS App Mesh Virtual Gateways that are configured without TLS encryption enabled. Virtual Gateways act as entry points to your service mesh, and lacking TLS encryption leaves network traffic vulnerable to eavesdropping and manipulation.

Weakness:

016 - Insecure encryption algorithm - SSL/TLS

Category: Information Collection

Detection Strategy

    Checks each Virtual Gateway in the specified AWS region within App Mesh

    Reports a vulnerability if a Virtual Gateway's listener configuration does not have TLS mode enabled

    Evaluates all Virtual Gateways across all App Meshes in the account for the given region

Severity v4.0

0.6

Low

Method ID

CSPM-6RTHW

Technique

CSPM

Target

AWS

Technology

APP_MESH

CWE ID(s)

CWE-327