Network misconfigurations

Security group allows unrestricted ingress access to port 3389 (RDP)


Network security groups (NSGs) act as virtual firewalls for your compute instances and other kinds of resources. An NSG consists of a set of ingress and egress security rules that specify the types of traffic allowed in and out. NSG security rules apply only to a set of VNICs (Virtual Network Interface Cards) of your choice in a single VCN (Virtual Cloud Network). Compared to security lists, NSGs let you separate your VCN's subnet architecture from your application security requirements. It was detected that the NSG {OciNetworkSecurityGroup.Name} under VCN {OciNetworkSecurityGroup.Vcn} allows unrestricted ingress access to port 3389 (RDP). To prevent unauthorized access or attacks on compute instances, it is advised to allow RDP access only from authorized CIDR blocks, rather than leaving them open to the internet (