EC2 instance does not enforce IMDSv2

Severity
Medium
Service
EC2
Check ID
EC2_IMDSV2_NOT_ENFORCED

What this check finds

The original metadata service that allows EC2s to assume IAM roles could allow an attacker to take over that role if they were able to find an SSRF vulnerability or proxy functionality on the instance. IMDSv2 should be enforced and not optional.

Passing looks like: IMDSv2 enforced.

How to fix it

Enforce IMDSv2 (token-required mode) on all EC2 instances.

AWS CLI

  1. aws ec2 modify-instance-metadata-options --instance-id INSTANCE_ID --http-tokens required --http-endpoint enabled
  2. For new instances, enforce via EC2 launch template or account-level default setting.

Names in capitals are placeholders for your own resource. Review a command before you run it.

AWS console

EC2 → Instances → select instance → Actions → Instance settings → Modify instance metadata options.

Compliance controls it is evidence for

A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works

Compliance controls mapped to EC2 instance does not enforce IMDSv2
FrameworkControls
CIS AWS Foundations Benchmark v5.0.0
  • 5.7 Ensure that the EC2 Metadata Service only allows IMDSv2
PCI-DSS v4.0.1
  • 2.2 System components are configured and managed securely
HIPAA Security Rule
  • 164.308(a)(5) Security Awareness — Protection from Malicious Software
SOC 2 — Trust Services Criteria
  • CC7.1 Threat and Vulnerability Detection
NIST SP 800-53 Rev5 (Moderate)
  • CM-6 Configuration Settings
  • SC-7 Boundary Protection
NIST Cybersecurity Framework 2.0
  • PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
  • PR.PS-01 Configuration management practices are applied
ISO/IEC 27001:2022 Annex A
  • A.8.9 Configuration management
  • A.8.20 Networks security

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More EC2 checks

All EC2 checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only