Description
Allowing Action: "*" in an AWS IoT policy broadly permits supported actions within the policy’s resource scope.
Potential impact
Unneeded device permissions can increase the impact of malfunction or compromised credentials.
Remediation
Specify only required actions, such as connecting, publishing or subscribing, and use the appropriate resource scope for each action.
Examples
The examples explicitly grant iot:Connect for a particular client. Actions and resources jointly determine access, so configure the actual client ID.
Before
yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
IoTPolicy:
Type: AWS::IoT::Policy
Properties:
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: "*"
Resource:
- arn:aws:iot:us-east-1:123456789012:client/client
PolicyName: PolicyName
After
yaml
AWSTemplateFormatVersion: 2010-09-09
Description: A sample template
Resources:
IoTPolicy:
Type: AWS::IoT::Policy
Properties:
PolicyDocument:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action:
- iot:Connect
Resource:
- arn:aws:iot:us-east-1:123456789012:client/client1
PolicyName: PolicyName