Aws Allow All Ingress
Description
Detects AWS Network Access Control Lists (NACLs) that allow inbound traffic from any IP address (0.0.0.0/0 or ::/0). This misconfiguration bypasses network-level access controls and could allow unauthorized access to resources within the VPC.
Detection Strategy
• Examines each Network ACL's inbound rules (where Egress=false)
• Reports a vulnerability if an inbound ALLOW rule contains 0.0.0.0/0 (IPv4) or ::/0 (IPv6) CIDR ranges
• Identifies affected resources by their Network ACL ID, AWS account, and region
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan.If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.