EC2 instance does not enforce IMDSv2
- Severity
- Medium
- Service
- EC2
- Check ID
- EC2_IMDSV2_NOT_ENFORCED
What this check finds
The original metadata service that allows EC2s to assume IAM roles could allow an attacker to take over that role if they were able to find an SSRF vulnerability or proxy functionality on the instance. IMDSv2 should be enforced and not optional.
Passing looks like: IMDSv2 enforced.
How to fix it
Enforce IMDSv2 (token-required mode) on all EC2 instances.
AWS CLI
aws ec2 modify-instance-metadata-options --instance-id INSTANCE_ID --http-tokens required --http-endpoint enabledFor new instances, enforce via EC2 launch template or account-level default setting.
Names in capitals are placeholders for your own resource. Review a command before you run it.
AWS console
EC2 → Instances → select instance → Actions → Instance settings → Modify instance metadata options.
Compliance controls it is evidence for
A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works
| Framework | Controls |
|---|---|
| CIS AWS Foundations Benchmark v5.0.0 |
|
| PCI-DSS v4.0.1 |
|
| HIPAA Security Rule |
|
| SOC 2 — Trust Services Criteria |
|
| NIST SP 800-53 Rev5 (Moderate) |
|
| NIST Cybersecurity Framework 2.0 |
|
| ISO/IEC 27001:2022 Annex A |
|
Checked on every scan
KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs
More EC2 checks
- HighAccount does not block public sharing of EBS snapshots
- HighAMI is publicly shared
- HighEBS snapshot is public
- HighEC2 instance CPU spiked abnormally — possible compromise or runaway process
- HighEC2 instance has an IAM role with admin privileges
- MediumAccount default for instance metadata does not require IMDSv2
- MediumEBS default encryption is not enabled for this region
- MediumEBS volume is not encrypted at rest