Vulnerabilidades em AWS

140 resultados
Análise Vexday

Com 69 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo CISA KEV, o perfil do AWS situa-se abaixo da média geral do catálogo nesse indicador, o que representa um panorama relativamente controlado em termos de ameaças imediatas. No entanto, 33 vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo elevado de descobertas recentes que exige acompanhamento contínuo. O tipo de falha mais recorrente é CWE-327 (uso de algoritmo criptográfico quebrado ou arriscado), padrão que tende a impactar a confidencialidade e integridade de dados em escala. A CVE mais relevante no momento, CVE-2025-0851, apresenta score EPSS de 0,23, e embora existam 3 CVEs com prova de conceito pública e 5 de severidade crítica, nenhuma delas atingiu exploração confirmada até o momento — condição que pode mudar rapidamente diante da disponibilidade de PoCs.

CVE-2025-11617MEDIUMBuffer Over-read when receiving IPv6 packets with incorrect payload length in FreeRTOS-Plus-TCPEPSS 0.3%CVE-2025-11616MEDIUMBuffer Over-read when receiving improperly sized ICMPv6 packets in FreeRTOS-Plus-TCPEPSS 0.3%CVE-2026-11401HIGHPrivilege Escalation in AWS Advanced Go Wrapper for Amazon Aurora PostgreSQLEPSS 0.3%CVE-2026-11400HIGHPrivilege Escalation in AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQLEPSS 0.3%CVE-2026-19642MEDIUMOut-of-bounds write in the Base64 decoder in Amazon aws-sdk-cppEPSS 0.3%CVE-2026-18394MEDIUMIncorrect authorization in Strands Agents Tools http_request proxy credential exfiltrationEPSS 0.3%CVE-2026-10740MEDIUMExcessive memory allocation in s2n-quicEPSS 0.3%CVE-2025-12815MEDIUMAn ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.EPSS 0.3%CVE-2026-18654MEDIUMDisabled SSH host key verification in Amazon AWS CLI EMR helper commandsEPSS 0.3%CVE-2026-18481MEDIUMStored XSS in Participant URL Field leads to Account Takeover via Session Token TheftEPSS 0.3%CVE-2026-92943CRITICALImproper validation of certificate with host mismatch in AWS IoT Device SDK for PythonEPSS 0.3%CVE-2025-2598MEDIUMAWS CDK CLI prints AWS credentials retrieved by custom credential pluginsEPSS 0.3%CVE-2026-18061MEDIUMImproper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper RemoteQueryCachePluginEPSS 0.3%CVE-2026-6966HIGHSignature Threshold Bypass in awslabs/tough Delegated RolesEPSS 0.3%CVE-2025-0508MEDIUMMD5 Hash Collision in SageMaker Workflow in aws/sagemaker-python-sdkEPSS 0.3%CVE-2026-85781MEDIUMUnverified access point ownership in Amazon EFS CSI DriverEPSS 0.3%CVE-2026-6911CRITICALAuthentication Bypass via Missing JWT Signature Verification in AWS Ops WheelEPSS 0.3%CVE-2026-1778HIGHTLS disabled by default in select aws/sagemaker-python-sdk configurationsEPSS 0.3%CVE-2026-4428CRITICALCRL Distribution Point Scope Check Logic Error in AWS-LCEPSS 0.3%CVE-2026-18655HIGHBroker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt InjectionEPSS 0.3%