7 Azure and AWS Misconfigurations guide
| Cloud Provider | Misconfiguration | Security risk | Remedial action |
|---|---|---|---|
| Azure front door has no WAF policy | Without a WAF, SQL injection, XSS, and CSRF attacks can reach backend services leading to data breaches. |
|
|
| AWS EC2 instance not configured with Instance Metadata Service v2 (IMDSv2) | EC2 instances without IMDSv2 are vulnerable to metadata service attacks, such as IAM credentials. |
|
|
| Azure Key Vault Allows Traffic from All Networks | **** | **** | |
| **** | **** | **** | |
| **** | **** | **** | |
| **** | **** | **** |
Zoho Corporation Pvt. Ltd. All rights reserved