logo

259 Lack of protection against deletion - DynamoDB


Description

The current configuration has no protection against deletion (recovery points in time). The deletion of DynamoDB instances deletes the information without the possibility of recovery.


Impact

Delete a DynamoDB instance by mistake or without having to go through additional validations.


Recommendation

Securely configure the Amazon Web Services service, enabling protection against accidental deletion with recovery points in time.


Threat

Internet attacker with access to the AWS console.


Expected Remediation Time

30 minutes.


Score 4.0

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

  • Attack vector: N
  • Attack complexity: L
  • Attack Requirements: N
  • Privileges required: H
  • User interaction: N
  • Confidentiality (VC): N
  • Integrity (VI): N
  • Availability (VA): H
  • Confidentiality (SC): N
  • Integrity (SI): N
  • Availability (SA): N

Threat 4.0

  • Exploit maturity: X

Requirements


Fixes


Last updated

2024/02/18