VPC peering route table allows broader CIDR than peer VPC
- Severity
- Medium
- Service
- VPC
- Check ID
- VPC_PEERING_ROUTE_BROAD_CIDR
What this check finds
A route table entry for a VPC peering connection uses a destination CIDR that is broader than the peer VPC's CIDR block. This violates least-privilege networking — traffic intended only for the peer VPC can be routed from a wider IP range, increasing blast radius if the peering connection is misused. CIS v1.4 §5.4.
Passing looks like: VPC peering routes scoped to peer CIDR.
How to fix it
Update the peering route to use the exact CIDR of the peer VPC rather than a supernet.
AWS CLI
aws ec2 replace-route --route-table-id RTB_ID --destination-cidr-block PEER_VPC_CIDR --vpc-peering-connection-id PCX_ID
Names in capitals are placeholders for your own resource. Review a command before you run it.
AWS console
VPC → Route tables → select table → Routes → Edit → change the destination to the peer VPC CIDR.
Compliance controls it is evidence for
A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works
| Framework | Controls |
|---|---|
| CIS AWS Foundations Benchmark v5.0.0 |
|
| NIST SP 800-53 Rev5 (Moderate) |
|
| NIST Cybersecurity Framework 2.0 |
|
| ISO/IEC 27001:2022 Annex A |
|
Checked on every scan
KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs