logo

Database

Azure Cosmos Db Public Network Access Enabled

Description

Detects Azure Cosmos DB accounts with insecure public network access configurations. A vulnerability exists when an account has public network access enabled without proper IP filtering rules or virtual network restrictions, potentially exposing the database to unauthorized access from the internet.

Weakness:

446 - Insecure service configuration - Azure

Category: Functionality Abuse

Detection Strategy

    Reports a vulnerability when public network access is enabled AND either:

    - No IP rules and no virtual network filtering are configured, allowing access from all networks

    - One or more invalid IP address or range rules are configured in the IP whitelist

Severity v4.0

1.7

Low

Method ID

CSPM-BORM4

Technique

CSPM

Target

AZURE

Technology

COSMOS_DB

CWE ID(s)

CWE-1188