Description
A security group allowing TCP port 22 from 0.0.0.0/0 or ::/0 permits SSH traffic from any internet address. External connections are possible when an internet route and a listening SSH service exist.
Potential impact
Unnecessary connection attempts and authentication attacks increase exposure to weaknesses in authentication or service configuration.
Remediation
Remove unrestricted address ranges and allow only the required administrator, VPN, or bastion sources. Remove the rule if direct SSH is unnecessary.
Examples
The examples narrow access to an approved management range. Do not trust an address merely because it is private; choose the range for the actual administrators.
Before
hcl
resource "aws_security_group" "example" {
name = "allow_tls"
description = "SSH port open"
ingress {
description = "SSH port open"
from_port = 22
to_port = 22
protocol = "tcp"
cidr_blocks = ["192.120.0.0/16", "0.0.0.0/0"]
}
}
After
hcl
resource "aws_security_group" "example" {
ingress {
description = "SSH from management network"
from_port = 22
to_port = 22
protocol = "tcp"
cidr_blocks = ["10.10.10.0/24"]
}
}