| name | cis-aws-compute-2.8 |
| description | Ensure the Use of IMDSv2 is Enforced on All Existing Instances |
| category | cis-compute |
| version | 1.1.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","compute","ec2","imdsv2","metadata","ssrf","instance-metadata"] |
| cis_id | 2.8 |
| cis_benchmark | CIS AWS Compute Services Benchmark v1.1.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-compute-2.7","cis-aws-compute-2.13"] |
| prerequisites | [] |
| severity_boost | {} |
Ensure the Use of IMDSv2 is Enforced on All Existing Instances
Description
Ensure the Instance Metadata Service Version 2 (IMDSv2) method is enabled on all running instances.
Rationale
The IMDSv2 method uses session-based controls to help protect access and control of Amazon Elastic Compute Cloud (Amazon EC2) instance metadata. With IMDSv2, controls can be implemented to restrict changes to instance metadata.
Impact
Once you enforce IMDSv2, then IMDSv1 no longer works, and applications that use IMDSv1 might not function correctly. Before enforcing IMDSv2, verify that any applications that use Amazon EC2 metadata are upgraded to a version that supports IMDSv2.
Audit Procedure
Using AWS CLI
- Run the describe-instances command:
aws ec2 describe-instances --region us-east-1 --output text --filter "Name=metadata-options.http-tokens,Values=optional" --query "Reservations[*].Instances[*].{Instance:InstanceId}"
- The output should look like this:
i-1234567abcdefghi0
i-1234567abcdefghi0
i-1234567abcdefghi0
The list above contains all the instances that have the metadata version set to optional which means either IMDSv1 or IMDSv2 can be used. Refer to the remediation below.
Repeat steps 1 - 2 for the other AWS regions.
Using AWS Console
- At this time the instance metadata setting for existing instances can only be reviewed and confirmed using AWS CLI.
Expected Result
The CLI command should return an empty list, indicating all instances have http-tokens set to required (enforcing IMDSv2). Any instances listed are using optional mode allowing IMDSv1.
Remediation
Using AWS CLI
- Run the modify-instance-metadata-options command using the list of Instances collected in the audit:
aws ec2 modify-instance-metadata-options --instance-id i-1234567abcdefghi0 --http-tokens required --http-endpoint enabled
- The output should show the information for the instance and the metadata changes:
{
"InstanceId": "i-1234567abcdefghi0",
"InstanceMetadataOptions":