logo

Database

Aws Password Expiration Unsafe

Description

Detects when AWS IAM account password policy is configured with an unsafe maximum password age that exceeds recommended duration. Having passwords that can be used for too long without requiring rotation increases the risk of credential compromise and unauthorized account access.

Weakness:

363 - Weak credential policy - Password strength

Category: Unexpected Injection

Detection Strategy

    Retrieves the IAM account password policy for the AWS account

    Checks if MaxPasswordAge in the password policy is set and exceeds 90 days

    Reports a vulnerability if password expiration period is too long or not enforced

Severity v4.0

2.7

Low

Method ID

CSPM-AFS3U

Technique

CSPM

Target

AWS

Technology

IAM

CWE ID(s)

CWE-521