logo

Database

Aws Policy Misconfigured

Description

Detects misconfigured AWS IAM policies that may grant excessive or insecure permissions. This detector analyzes policy statements within IAM policies to identify overly permissive configurations that could allow unintended access to AWS resources.

Weakness:

325 - Excessive privileges - Wildcards

Category: Access Subversion

Detection Strategy

    Scans all IAM policies in the AWS account

    Examines each policy's default version and its statements

    Alerts if policy statements contain overly permissive configurations like Action:"*" or Resource:"*"

    Reports issues when policy statements grant broad administrative privileges or sensitive service access

    Identifies policies that don't follow the principle of least privilege

Severity v4.0

0.5

Low

Method ID

CSPM-CAIWI

Technique

CSPM

Target

AWS

Technology

IAM

CWE ID(s)

CWE-250