logo

Database

Azure Synapse Firewall Allows Public Access

Description

Detects Azure Synapse workspaces that have firewall rules allowing unrestricted public network access. This configuration can expose the Synapse workspace to potential unauthorized access from the internet, increasing the risk of data breaches and unauthorized modifications.

Weakness:

392 - Security controls bypass or absence - Firewall

Category: Functionality Abuse

Detection Strategy

    Checks if public network access is explicitly enabled for the Synapse workspace

    Verifies if the firewall rule's start and end IP addresses are configured

    Reports a vulnerability when public access is enabled and the IP range configuration is invalid or overly permissive

Severity v4.0

1.7

Low

Method ID

CSPM-EAELS

Technique

CSPM

Target

AZURE

Technology

SYNAPSE

CWE ID(s)

CWE-602