Network misconfigurations

Amazon ECS service configured to assign public IP addresses automatically

Platform(s)
Compliance Frameworks

AWS Foundational Security Best Practices Controls, CCPA, CPRA, Data Security Posture Management (DSPM) Best Practices, iso_27001_2022, iso_27002_2022, Mitre ATT&CK, mpa, NIST 800-171, NIST 800-53, PDPA, UK Cyber Essentials

Description

ECS is a container management service that allows you to run, stop, and manage containers on a cluster. It was detected that ECS service {AwsEcsService} is configured to assign public IP addresses automatically. ECS instances with a public IP address are reachable from the internet and may allow unintended access.