Security group ingress allows all source addresses

Limit security group ingress sources and ports to the service’s intended use.

Description

In security group ingress rules, 0.0.0.0/0 allows all IPv4 sources and ::/0 allows all IPv6 sources. Actual internet reachability also depends on public addressing, routes, and other network controls. Distinguish public web services from administrative or internal services.

Potential impact

An internet-reachable service that does not need external access may receive unnecessary connection attempts and be exposed to exploitation of service vulnerabilities.

Remediation

For services that do not need public access, restrict rules to approved client CIDRs or suitable security group references. Allow only required ports and check both IPv4 and IPv6 rules. Test legitimate connectivity and rejection of unwanted access after the change.

Examples

This example is for an HTTP service used only by internal clients. Supply the actual VPC ID as myVPC and an approved client IPv4 range as AllowedClientCidr. Attach the security group to the relevant resources separately.

Before

yaml
Parameters:
  myVPC:
    Type: AWS::EC2::VPC::Id
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: HTTP
      VpcId: !Ref myVPC
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 80
          ToPort: 80
          CidrIp: 0.0.0.0/0

After

yaml
Parameters:
  myVPC:
    Type: AWS::EC2::VPC::Id
  AllowedClientCidr:
    Type: String
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: HTTP
      VpcId: !Ref myVPC
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 80
          ToPort: 80
          CidrIp: !Ref AllowedClientCidr

References