logo

Database

Aws Intercontainer Encryption Disabled

Description

Detects AWS SageMaker training jobs that have inter-container traffic encryption disabled. When disabled, communication between training containers is not encrypted, potentially exposing sensitive data and model parameters to unauthorized access within the network.

Weakness:

165 - Insecure service configuration - AWS

Category: Functionality Abuse

Detection Strategy

    Examines all SageMaker training jobs in the specified AWS region

    Reports a vulnerability when a training job has EnableInterContainerTrafficEncryption set to false

    Identifies affected resources by their Training Job ARN and includes the encryption setting value in the report

Severity v4.0

1.3

Low

Method ID

CSPM-AREES

Technique

CSPM

Target

AWS

Technology

SAGEMAKER

CWE ID(s)

CWE-306