Description
An EC2 security group that allows an administrative or data-service port, such as Redis, from 0.0.0.0/0 or ::/0 includes every address in that rule’s source range. Actual internet connectivity also depends on addressing, routing, a listening service and other network controls.
Allow only required internal-service connections and configure authentication and encryption separately. A security group allowance does not grant permission to access data.
Potential impact
- Reachable services can receive more credential attacks or attempts to exploit vulnerabilities from external clients.
- Weak authentication or a vulnerable service can lead to data disclosure or disruption.
Remediation
- Remove sensitive-port rules covering all IPv4 or IPv6 addresses, or narrow them to actual clients.
- Use application security group references or private administrative paths where supported. Review additional permissions from every attached group.
- Test required and blocked connections after the change, and review authentication, patching and encryption.
Examples
Supply a subnet in the same VPC and a compatible AMI. These examples demonstrate security group attachment; they do not install Redis. Replace 10.0.20.0/24 with the actual application range and configure required routing and egress separately.
Before
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
VpcId:
Type: AWS::EC2::VPC::Id
SubnetId:
Type: AWS::EC2::Subnet::Id
ImageId:
Type: AWS::EC2::Image::Id
Resources:
UnsafeSecGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Allow Redis from the internet
VpcId: !Ref VpcId
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 6379
ToPort: 6379
CidrIp: 0.0.0.0/0
EC2Instance:
Type: AWS::EC2::Instance
Properties:
ImageId: !Ref ImageId
SubnetId: !Ref SubnetId
InstanceType: t3.medium
SecurityGroupIds:
- !Ref UnsafeSecGroup
TCP 6379 is allowed from every IPv4 address. If the service is reachable, it can receive unwanted connection attempts.
After
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
VpcId:
Type: AWS::EC2::VPC::Id
SubnetId:
Type: AWS::EC2::Subnet::Id
ImageId:
Type: AWS::EC2::Image::Id
Resources:
SafeSecGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Allow Redis only from the application network
VpcId: !Ref VpcId
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 6379
ToPort: 6379
CidrIp: 10.0.20.0/24
EC2Instance:
Type: AWS::EC2::Instance
Properties:
ImageId: !Ref ImageId
SubnetId: !Ref SubnetId
InstanceType: t3.medium
SecurityGroupIds:
- !Ref SafeSecGroup
The same port is limited to the application range. Verify that every client in that range needs the connection.