logo

Database

Aws Master Keys Exposed

Description

Detects AWS KMS master keys that have overly permissive key policies which could allow unauthorized access to sensitive encryption keys. This vulnerability could enable unauthorized users to access, use, or manage critical KMS keys, potentially compromising the security of encrypted data.

Weakness:

325 - Excessive privileges - Wildcards

Category: Access Subversion

Detection Strategy

    Scans all KMS key aliases in the specified AWS region

    For each KMS key, retrieves and analyzes its associated key policies

    Checks if any policy statements grant overly permissive access (e.g., access to everyone/public)

    Reports a vulnerability if key policies allow broad access patterns that could expose the master key to unauthorized users

Severity v4.0

0.5

Low

Method ID

CSPM-AEYSE

Technique

CSPM

Target

AWS

Technology

KMS

CWE ID(s)

CWE-250