logo

Database

Aws Root Access Keys

Description

Detects if the AWS root account has any active access keys. The root account has unrestricted access to all AWS resources, so having active access keys associated with it poses a significant security risk as these credentials could be exposed or misused.

Weakness:

165 - Insecure service configuration - AWS

Category: Functionality Abuse

Detection Strategy

    Checks the AWS IAM credential report for the root user account

    Reports a vulnerability if either access_key_1 or access_key_2 is active for the root account

    Best practice is to not have any active access keys for the root account - instead create IAM users with appropriate permissions

Severity v4.0

1.3

Low

Method ID

CSPM-AOTC1

Technique

CSPM

Target

AWS

Technology

IAM

CWE ID(s)

CWE-306