logo

Database

Aws Not Requires Numbers

Description

Detects when AWS IAM password policies don't require numeric characters in passwords. Not requiring numbers in passwords reduces password complexity and security, making accounts more vulnerable to unauthorized access through password attacks.

Weakness:

363 - Weak credential policy - Password strength

Category: Unexpected Injection

Detection Strategy

    Checks the AWS account's IAM password policy configuration

    Reports a vulnerability if the 'RequireNumbers' setting is explicitly set to false

    Reports a vulnerability if the 'RequireNumbers' setting is missing from the password policy

Severity v4.0

1.7

Low

Method ID

CSPM-EOSTE

Technique

CSPM

Target

AWS

Technology

IAM

CWE ID(s)

CWE-521