Description
A port open to all source addresses needs a clear service purpose and intended audience. An uncommon port number does not by itself prove that a service is unsafe or its purpose unknown. Identify the actual listener, its owner and the need for public access.
Potential impact
- Unused or temporary services may be exposed to unnecessary external connections.
- Rules without a clear purpose or owner make access scope and change impact harder to manage.
Remediation
- Identify the service, owner and required clients, and remove unnecessary public rules.
- Where public access is needed, restrict actual sources, protocols and ports to the required scope, documenting the reason and review deadline.
- Review IPv4, IPv6 and all attached security groups, verifying that required connections succeed and unwanted connections are blocked.
Examples
These excerpts compare ingress scope for a TCP 5001 service. Identify the actual service, VPC and attachments separately, and replace the private example range with approved client addresses.
Before
resource "aws_security_group" "custom_service" {
name = "allow-custom-port"
description = "Unknown port exposed"
ingress {
from_port = 5001
to_port = 5001
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"]
}
}
This allows TCP 5001 from all IPv4 sources. The port number alone does not determine the service or whether public access is needed.
After
resource "aws_security_group" "custom_service" {
name = "allow-custom-port"
description = "Unknown port restricted"
ingress {
from_port = 5001
to_port = 5001
protocol = "tcp"
cidr_blocks = ["10.20.0.0/24"]
}
}
This restricts sources to 10.20.0.0/24. Check whether the entire range is needed and whether another security group allows broader access.