165 – Insecure service configuration - AWS
Description
Because of a misconfiguration in the AWS services, it is possible to identify and/or try to access resources, functionalities, network segments and ports.
Impact
- Identify ports, services and network segments. - Try to access the services found. - Get credentials, services and files information.
Recommendation
Securely configure the vulnerable service to be accessed only by authorized users.
Threat
External attacker with credentials.
Expected Remediation Time
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: N
- Attack complexity: L
- Attack Requirements: N
- Privileges required: L
- User interaction: N
- Confidentiality (VC): L
- Integrity (VI): L
- Availability (VA): N
- Confidentiality (SC): N
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
- Exploit maturity: P