Impact
A server‑side request forgery flaw in Amazon AWS Systems Manager Agent allows an authenticated remote user to craft destination host values that use alternate representations of denied link‑local addresses. By bypassing the private link‑local endpoints and retrieve the instance's temporary IAM role credentials. The attacker can then act with those permissions from outside the instance, potentially accessing or modifying resources and data the role is allowed to control.
Affected Systems
AWS Systems Manager Agent (SSM Agent) versions earlier than 3.3.4851.0 on all supported platforms are affected. The vulnerability exists in the session manager port forwarding implementation of the agent.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the attacker must be authenticated with SSM permissions, the exploit requires valid credentials but can be carried out remotely by abusing the port‑forwarding feature. No public exploit has been reported, but the combination of authenticated access and the ability to obtain temporary IAM credentials presents a significant risk.
OpenCVE Enrichment