Description
Allowing TCP 22 from 0.0.0.0/0 or ::/0 makes every address in that family an allowed SSH source. Actual access also requires a network path and an SSH service; the security group rule does not bypass SSH authentication.
Permit SSH only from required management addresses or security groups. A narrow rule does not restrict access if another attached group broadly permits port 22 or all protocols.
Potential impact
- Reachable management ports can receive scans and brute-force attempts.
- Leaked keys or weak account and service settings can lead to server compromise.
Remediation
- Restrict TCP 22 to approved management addresses or suitable security groups, reviewing both IPv4 and IPv6 permissions.
- Remove unnecessary broad rules. Where appropriate, use a restricted bastion or Session Manager with the required IAM permissions, agent, and connectivity.
- Manage SSH authentication, key revocation and rotation, and access records. Test that required management connections still work.
Examples
Replace the VPC ID with the actual value. Instances and routing are omitted; ensure the previous broad rule does not remain after deployment.
Before
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: SSH security group
VpcId: vpc-0123456789abcdef0
OpenSSHIngress:
Type: AWS::EC2::SecurityGroupIngress
Properties:
GroupId: !Ref InstanceSecurityGroup
IpProtocol: tcp
FromPort: 20
ToPort: 22
CidrIpv6: "::/0"
TCP 20–22 is allowed from every IPv6 address, including SSH.
After
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: SSH security group
VpcId: vpc-0123456789abcdef0
RestrictedSSHIngress:
Type: AWS::EC2::SecurityGroupIngress
Properties:
GroupId: !Ref InstanceSecurityGroup
IpProtocol: tcp
FromPort: 22
ToPort: 22
CidrIp: 203.0.113.10/32
Only TCP 22 from one IPv4 address is allowed. Replace the documentation address 203.0.113.10/32 with the actual management source and restrict any required IPv6 management path separately.