Security group allows unrestricted outbound traffic

Review unrestricted outbound permissions and retain only required destinations, protocols, and ports.

Description

Combining IpProtocol: "-1" with 0.0.0.0/0 or ::/0 permits every protocol to every destination in that address family. When routes and other network conditions also permit communication, it becomes harder to limit a compromised workload's external connections or data transfer.

Identify actual external dependencies and specify the necessary permissions. A narrow security group rule does not cancel broader permissions in another rule or attached group.

Potential impact

  • A malicious process can connect to a command server or unapproved external service.
  • Removing broad permissions indiscriminately can interrupt updates, log delivery, or business services.

Remediation

  • Restrict destinations, protocols, and ports to actual requirements and review all attached groups.
  • Check deployed rules: omitting outbound rules when creating a group can add default allow-all permissions.
  • Use suitable proxies, firewalls, or VPC endpoints and test legitimate connections. Security group state tracking permits responses to allowed inbound connections.

Examples

The VPC is omitted, so a default VPC must exist in the Region. The group description does not restrict the actual rules.

Before

yaml
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Enable SSH access via port 22
      SecurityGroupEgress:
        - IpProtocol: "-1"
          CidrIp: 0.0.0.0/0

All protocols are allowed to every IPv4 destination.

After

yaml
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Enable SSH access via port 22
      SecurityGroupEgress:
        - IpProtocol: tcp
          FromPort: 443
          ToPort: 443
          CidrIp: 10.0.0.0/8

This rule permits TCP 443 to 10.0.0.0/8. That is still a broad private range; narrow it to required destinations and verify TLS and authentication separately.

References