Junglewise Threat Intelligence

AWS CLI and SDK IMDS impersonation on non-EC2 nodes

Severity: info · CVSS 0 · Published 2025-10-08

Technologies: Amazon AWS. Vendors: AWS, Amazon.

Executive brief

AWS tools like the Command Line Interface (CLI) and SDKs may be tricked into using incorrect security credentials when run on servers outside of the AWS cloud environment. If an attacker has control over the local network where these tools are running, they can impersonate the AWS metadata service to provide their own credentials, potentially causing the tools to interact with an attacker-controlled AWS account instead of the intended one. This could lead to data being sent to the wrong location or administrative actions being performed in an unexpected environment.

Technical details

AWS tools (CLI, SDK, SSM Agent) are designed to automatically check the Instance Metadata Service (IMDS) at the link-local address 169.254.169.254 for credentials. When these tools are executed on non-EC2 compute nodes (such as on-premises servers), an attacker with a privileged network position can host a rogue IMDS endpoint. This rogue service can serve credentials for a different AWS account, leading the tools to perform operations against an unintended environment. The issue affects both IMDSv1 and IMDSv2. Mitigation involves following specific configuration guides for tools used outside the AWS data perimeter and monitoring on-premises networks for traffic destined for the 169.254.169.254 or fd00:ec2::254 addresses.

Affected products

  • AWS AWS CLI
  • AWS AWS SDK
  • AWS SSM Agent

Timeline

  • 2025-10-08: advisory: Initial publication of AWS-2025-021

References

Related threats