Security group allows SSH from all addresses

Restrict SSH management access to required sources and strengthen authentication and key management.

Description

Allowing TCP 22 from 0.0.0.0/0 or ::/0 makes every address in that family an allowed SSH source. Actual access also requires a network path and an SSH service; the security group rule does not bypass SSH authentication.

Permit SSH only from required management addresses or security groups. A narrow rule does not restrict access if another attached group broadly permits port 22 or all protocols.

Potential impact

  • Reachable management ports can receive scans and brute-force attempts.
  • Leaked keys or weak account and service settings can lead to server compromise.

Remediation

  • Restrict TCP 22 to approved management addresses or suitable security groups, reviewing both IPv4 and IPv6 permissions.
  • Remove unnecessary broad rules. Where appropriate, use a restricted bastion or Session Manager with the required IAM permissions, agent, and connectivity.
  • Manage SSH authentication, key revocation and rotation, and access records. Test that required management connections still work.

Examples

Replace the VPC ID with the actual value. Instances and routing are omitted; ensure the previous broad rule does not remain after deployment.

Before

yaml
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: SSH security group
      VpcId: vpc-0123456789abcdef0
  OpenSSHIngress:
    Type: AWS::EC2::SecurityGroupIngress
    Properties:
      GroupId: !Ref InstanceSecurityGroup
      IpProtocol: tcp
      FromPort: 20
      ToPort: 22
      CidrIpv6: "::/0"

TCP 20–22 is allowed from every IPv6 address, including SSH.

After

yaml
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: SSH security group
      VpcId: vpc-0123456789abcdef0
  RestrictedSSHIngress:
    Type: AWS::EC2::SecurityGroupIngress
    Properties:
      GroupId: !Ref InstanceSecurityGroup
      IpProtocol: tcp
      FromPort: 22
      ToPort: 22
      CidrIp: 203.0.113.10/32

Only TCP 22 from one IPv4 address is allowed. Replace the documentation address 203.0.113.10/32 with the actual management source and restrict any required IPv6 management path separately.

References