Security group egress allows all destination addresses

Restrict outbound destinations to the required scope and review permissions in other attached security groups.

Description

An outbound destination of 0.0.0.0/0 or ::/0 permits every destination in that address family. The rule's protocol and port settings still apply, and actual connectivity also requires routing and other network conditions.

Unnecessarily broad destinations make malware communication and unapproved external connections harder to limit. Identify required external services and update paths before setting restrictions. Security groups are stateful, so responses to allowed inbound requests do not require separate outbound rules.

Potential impact

  • A compromised workload can connect externally or transfer data over the permitted protocols and ports.
  • Indiscriminate restrictions can interrupt legitimate external service connections.

Remediation

  • Use required destination CIDRs, supported security group references, or prefix lists, and restrict ports.
  • Review all attached security groups and both address families. Adding a narrow rule does not remove a broader existing permission.
  • Check external dependencies and test required connections. Omitting outbound rules when creating a group can add default allow-all rules.

Examples

These excerpts omit the VPC, so a default VPC must exist in the Region. Adapt destination addresses to the actual requirements.

Before

yaml
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Allow http to client host
      SecurityGroupEgress:
        - IpProtocol: tcp
          FromPort: 80
          ToPort: 80
          CidrIp: 0.0.0.0/0

TCP 80 is allowed to every IPv4 destination. This is not an all-protocol rule.

After

yaml
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Allow http to client host
      SecurityGroupEgress:
        - IpProtocol: tcp
          FromPort: 80
          ToPort: 80
          CidrIp: 192.0.2.0/24

This narrows the rule's destinations. Replace the documentation range 192.0.2.0/24 with the actual permitted range.

References