logo

Database

Azure Cosmos Db Public Network Access Enabled

Description

Detects Azure Cosmos DB accounts with insecure public network access configurations. A vulnerability exists when an account has public network access enabled without proper IP filtering rules or virtual network restrictions, potentially exposing the database to unauthorized access from the internet.

Weakness:

446 - Insecure service configuration - Azure

Category: Functionality Abuse

Detection Strategy

    Reports a vulnerability when public network access is enabled AND either:

    - No IP rules and no virtual network filtering are configured, allowing access from all networks

    - One or more invalid IP address or range rules are configured in the IP whitelist