AWS security group allows ingress from all source addresses

Separate ingress scope for public services from internal-only services.

Description

An ingress rule allowing 0.0.0.0/0 or ::/0 admits every source address for the specified protocols and ports. Even a single open port can be too broad for an internal-only service. Actual internet reachability depends on attached resources and network paths.

Some public services, such as websites, need to accept all clients. Confirm that purpose and separate their access from management, database and internal API access.

Potential impact

  • Internal-only services may face unnecessary external connections or password-guessing attempts.
  • Broad source permissions combined with a vulnerable service can lead to data exposure or disruption.

Remediation

  • Remove all-address rules for internal services, permitting approved client ranges or an appropriate application security group as the source.
  • Use separate rules and groups for public services, allowing only required protocols and ports and reviewing both IPv4 and IPv6 scope.
  • Review all attached security groups and paths, then test that required connections succeed and unwanted ones are blocked.

Examples

This is a security-group excerpt for a service using TCP 3306. Verify the actual database port, VPC and attachments, and replace the private example range with approved application addresses.

Before

hcl
resource "aws_security_group" "database_access" {
  ingress {
    from_port   = 3306
    to_port     = 3306
    protocol    = "tcp"
    cidr_blocks = ["0.0.0.0/0"]
  }
}

This allows inbound TCP 3306 from every IPv4 source. It does not open every port or bypass database authentication.

After

hcl
resource "aws_security_group" "database_access" {
  ingress {
    from_port   = 3306
    to_port     = 3306
    protocol    = "tcp"
    cidr_blocks = ["10.0.0.0/16"]
  }
}

This narrows sources to 10.0.0.0/16. The example range is still broad; restrict it to actual database clients.

References