logo

Database

Aws Replication Publicly Accessible

Description

Detects AWS Database Migration Service (DMS) replication instances that are configured to be publicly accessible from the internet. Public DMS replication instances can expose sensitive database migration infrastructure to unauthorized access and potential attacks from the internet.

Weakness:

165 - Insecure service configuration - AWS

Category: Functionality Abuse

Detection Strategy

    Scans all DMS replication instances in the specified AWS region

    Reports a vulnerability if a replication instance has the 'PubliclyAccessible' setting enabled (set to true)

    Each vulnerable instance is reported with its unique ARN identifier and current public accessibility status