Network ACL allows unrestricted ingress to SSH (22) or RDP (3389)

Severity
Medium
Service
VPC
Check ID
NACL_ALLOWS_UNRESTRICTED_SSH_RDP

What this check finds

A NACL ALLOW rule that permits traffic from 0.0.0.0/0 or ::/0 to port 22 (SSH) or 3389 (RDP) exposes every subnet associated with that NACL to brute-force and credential-stuffing attacks from the entire internet. NACLs are the subnet-level firewall and should restrict administrative port access to known CIDRs.

Passing looks like: Network ACLs restrict SSH/RDP ingress.

How to fix it

Remove or restrict the ALLOW rule for port 22 or 3389 from 0.0.0.0/0 in the NACL. Replace with a rule that allows only known management IP ranges.

AWS CLI

  1. aws ec2 replace-network-acl-entry --network-acl-id ACL_ID --rule-number RULE_NUM --protocol tcp --rule-action allow --ingress --cidr-block MANAGEMENT_CIDR --port-range From=22,To=22

Names in capitals are placeholders for your own resource. Review a command before you run it.

AWS console

VPC → Network ACLs → select NACL → Inbound rules → Edit.

Compliance controls it is evidence for

A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works

Compliance controls mapped to Network ACL allows unrestricted ingress to SSH (22) or RDP (3389)
FrameworkControls
CIS AWS Foundations Benchmark v5.0.0
  • 5.2 Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
NIST SP 800-53 Rev5 (Moderate)
  • AC-17 Remote Access
  • SC-7 Boundary Protection
NIST Cybersecurity Framework 2.0
  • PR.AA-05 Access permissions and authorizations are enforced with least privilege
  • PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
ISO/IEC 27001:2022 Annex A
  • A.6.7 Remote working
  • A.8.20 Networks security

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More VPC checks

All VPC checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only