Description
An unnecessarily broad inbound TCP or UDP range can let permitted sources reach unintended services. Actual exposure also depends on listening services, routing, and other network controls.
Set FromPort and ToPort to the same value when only one port is required. Ranges are valid for services that need multiple ports, so do not remove them indiscriminately. For ICMP, these fields describe a type and code rather than ports.
Potential impact
- Services listening on unnecessarily allowed ports can become targets for scanning or attacks.
- Closing ports without checking requirements can interrupt legitimate client connections.
Remediation
- Identify service requirements and allow a single TCP or UDP port or the smallest required range.
- Restrict source CIDRs or security groups to required clients, and review permissions in other attached groups.
- Remove unused permissions, then test legitimate connectivity, service authentication, and authorization.
Examples
These excerpts omit TargetSG and the required source. A real rule must include one source CIDR, prefix list, or security group.
Before
Resources:
InboundRule:
Type: AWS::EC2::SecurityGroupIngress
Properties:
IpProtocol: tcp
FromPort: 0
ToPort: 65535
GroupId: !GetAtt TargetSG.GroupId
Once a source is supplied, this allows every TCP port.
After
Resources:
InboundRule:
Type: AWS::EC2::SecurityGroupIngress
Properties:
IpProtocol: tcp
FromPort: 443
ToPort: 443
GroupId: !GetAtt TargetSG.GroupId
This rule is restricted to TCP 443. The port number does not configure HTTPS or authentication; check the actual service settings.