Description
Combining IpProtocol: "-1" with 0.0.0.0/0 or ::/0 permits every protocol to every destination in that address family. When routes and other network conditions also permit communication, it becomes harder to limit a compromised workload's external connections or data transfer.
Identify actual external dependencies and specify the necessary permissions. A narrow security group rule does not cancel broader permissions in another rule or attached group.
Potential impact
- A malicious process can connect to a command server or unapproved external service.
- Removing broad permissions indiscriminately can interrupt updates, log delivery, or business services.
Remediation
- Restrict destinations, protocols, and ports to actual requirements and review all attached groups.
- Check deployed rules: omitting outbound rules when creating a group can add default allow-all permissions.
- Use suitable proxies, firewalls, or VPC endpoints and test legitimate connections. Security group state tracking permits responses to allowed inbound connections.
Examples
The VPC is omitted, so a default VPC must exist in the Region. The group description does not restrict the actual rules.
Before
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Enable SSH access via port 22
SecurityGroupEgress:
- IpProtocol: "-1"
CidrIp: 0.0.0.0/0
All protocols are allowed to every IPv4 destination.
After
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Enable SSH access via port 22
SecurityGroupEgress:
- IpProtocol: tcp
FromPort: 443
ToPort: 443
CidrIp: 10.0.0.0/8
This rule permits TCP 443 to 10.0.0.0/8. That is still a broad private range; narrow it to required destinations and verify TLS and authentication separately.