Security group allows SSH from the entire internet

Limit SSH access to approved management networks.

Description

A security group allowing TCP port 22 from 0.0.0.0/0 or ::/0 permits SSH traffic from any internet address. External connections are possible when an internet route and a listening SSH service exist.

Potential impact

Unnecessary connection attempts and authentication attacks increase exposure to weaknesses in authentication or service configuration.

Remediation

Remove unrestricted address ranges and allow only the required administrator, VPN, or bastion sources. Remove the rule if direct SSH is unnecessary.

Examples

The examples narrow access to an approved management range. Do not trust an address merely because it is private; choose the range for the actual administrators.

Before

hcl
resource "aws_security_group" "example" {
  name        = "allow_tls"
  description = "SSH port open"

  ingress {
    description = "SSH port open"
    from_port   = 22
    to_port     = 22
    protocol    = "tcp"
    cidr_blocks = ["192.120.0.0/16", "0.0.0.0/0"]
  }
}

After

hcl
resource "aws_security_group" "example" {
  ingress {
    description = "SSH from management network"
    from_port   = 22
    to_port     = 22
    protocol    = "tcp"
    cidr_blocks = ["10.10.10.0/24"]
  }
}

References