Description
An Azure NSG rule allowing inbound TCP port 22 from source * does not restrict SSH source addresses.
Potential impact
An SSH service reachable through a public route can be exposed to unnecessary login attempts and password guessing.
Remediation
Limit sources to required management IP addresses or subnets, or use a management path such as Azure Bastion. Check associated NSGs and rule priorities together.
Examples
Replace the documentation address 203.0.113.10/32 with the actual management address. Reachability depends on routing and the complete set of effective rules.
Before
bicep
resource security_group 'Microsoft.Network/networkSecurityGroups@2020-11-01' = {
name: 'security-group'
location: resourceGroup().location
properties: {
securityRules: [
{
properties: {
protocol: 'Tcp'
sourcePortRange: '*'
destinationPortRange: '22'
sourceAddressPrefix: '*'
destinationAddressPrefix: '*'
access: 'Allow'
priority: 301
direction: 'Inbound'
}
name: 'security-rule'
}
]
}
}
After
bicep
resource security_group 'Microsoft.Network/networkSecurityGroups@2020-11-01' = {
name: 'security-group'
location: resourceGroup().location
properties: {
securityRules: [
{
properties: {
protocol: 'Tcp'
sourcePortRange: '*'
destinationPortRange: '22'
sourceAddressPrefix: '203.0.113.10/32'
destinationAddressPrefix: '*'
access: 'Allow'
priority: 301
direction: 'Inbound'
}
name: 'security-rule'
}
]
}
}