Description
Allowing all sources on port 3389, used by RDP, can invite unnecessary connection attempts to an administrative service. Actual access also depends on the target's network path, RDP service and host firewall. Reachability does not bypass user authentication.
Potential impact
- An externally reachable RDP service may receive brute-force attempts or sign-ins using leaked credentials.
- A vulnerable service or weak account controls can increase the risk of host and data compromise.
Remediation
- Identify the resources and administrative clients that need RDP. Allow only the required protocols and ports from approved CIDRs or supported security group references.
- Use controlled administration paths such as a VPN rather than directly opening management ports to the internet. Review all attached groups, IPv4 and IPv6 paths, the host firewall and authentication.
- Establish the required management path before changing rules, then test permitted and denied connections. Check authentication logs and unusual attempts on exposed services too.
Examples
Provide the actual VPC and management-client range as vpc_id and management_cidr, and configure AWS authentication in the execution environment. These alternatives manage the same group; resource attachments and management paths are separate prerequisites.
Before
- name: example ec2 group
amazon.aws.ec2_security_group:
name: example2
description: an example EC2 group
vpc_id: "{{ vpc_id }}"
region: eu-west-1
rules:
- proto: tcp
ports: 3389
cidr_ip: 0.0.0.0/0
TCP port 3389 is allowed from every IPv4 source.
After
- name: example ec2 group
amazon.aws.ec2_security_group:
name: example2
description: an example EC2 group
vpc_id: "{{ vpc_id }}"
region: eu-west-1
rules:
- proto: tcp
ports: 3389
cidr_ip: "{{ management_cidr }}"
Only the approved management-client range is allowed. Avoid an unnecessarily broad management_cidr and verify that it matches the actual source addresses on the management path.