EC2 security group exposes a sensitive port to all addresses

Restrict ingress to EC2 administration and data-service ports to required clients.

Description

An EC2 security group that allows an administrative or data-service port, such as Redis, from 0.0.0.0/0 or ::/0 includes every address in that rule’s source range. Actual internet connectivity also depends on addressing, routing, a listening service and other network controls.

Allow only required internal-service connections and configure authentication and encryption separately. A security group allowance does not grant permission to access data.

Potential impact

  • Reachable services can receive more credential attacks or attempts to exploit vulnerabilities from external clients.
  • Weak authentication or a vulnerable service can lead to data disclosure or disruption.

Remediation

  • Remove sensitive-port rules covering all IPv4 or IPv6 addresses, or narrow them to actual clients.
  • Use application security group references or private administrative paths where supported. Review additional permissions from every attached group.
  • Test required and blocked connections after the change, and review authentication, patching and encryption.

Examples

Supply a subnet in the same VPC and a compatible AMI. These examples demonstrate security group attachment; they do not install Redis. Replace 10.0.20.0/24 with the actual application range and configure required routing and egress separately.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  VpcId:
    Type: AWS::EC2::VPC::Id
  SubnetId:
    Type: AWS::EC2::Subnet::Id
  ImageId:
    Type: AWS::EC2::Image::Id
Resources:
  UnsafeSecGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Allow Redis from the internet
      VpcId: !Ref VpcId
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 6379
          ToPort: 6379
          CidrIp: 0.0.0.0/0
  EC2Instance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: !Ref ImageId
      SubnetId: !Ref SubnetId
      InstanceType: t3.medium
      SecurityGroupIds:
        - !Ref UnsafeSecGroup

TCP 6379 is allowed from every IPv4 address. If the service is reachable, it can receive unwanted connection attempts.

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  VpcId:
    Type: AWS::EC2::VPC::Id
  SubnetId:
    Type: AWS::EC2::Subnet::Id
  ImageId:
    Type: AWS::EC2::Image::Id
Resources:
  SafeSecGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Allow Redis only from the application network
      VpcId: !Ref VpcId
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 6379
          ToPort: 6379
          CidrIp: 10.0.20.0/24
  EC2Instance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: !Ref ImageId
      SubnetId: !Ref SubnetId
      InstanceType: t3.medium
      SecurityGroupIds:
        - !Ref SafeSecGroup

The same port is limited to the application range. Verify that every client in that range needs the connection.

References