logo

Database

Aws Opensearch Insecure Tls Version

Description

Detects AWS OpenSearch domains configured with outdated and insecure TLS protocol versions (TLS 1.0 or TLS 1.1). Using these legacy TLS versions makes the domain vulnerable to known cryptographic attacks and man-in-the-middle exploits.

Weakness:

016 - Insecure encryption algorithm - SSL/TLS

Category: Information Collection

Detection Strategy

    Scans all OpenSearch domains in the specified AWS region

    Checks the TLSSecurityPolicy configuration for each domain

    Reports a vulnerability if the domain uses Policy-TLS-1-0 or Policy-TLS-1-1

    Each vulnerability includes the domain's ARN and the specific insecure TLS policy being used

Severity v4.0

0.6

Low

Method ID

CSPM-ERLNW

Technique

CSPM

Target

AWS

Technology

OPENSEARCH

CWE ID(s)

CWE-327