Network misconfigurations

Allowed SSH access from the internet

Risk Level

Informational (4)

Platform(s)

Description

Firewall rules are defined at the VPC network level and are specific to the network in which they are defined. The rules themselves cannot be shared among networks. Firewall rules only support IPv4 traffic. When specifying a source for an ingress rule or a destination for an egress rule by address, only an IPv4 address or IPv4 block in CIDR notation can be used. Generic (0.0.0.0/0) incoming traffic from the internet to VPC or VM instance using SSH on Port 22 can be avoided.
  • Recommended Mitigation

    Change firewall rules to restrict SSH access from the Internet to a specific IP Range.