logo

Database

Aws Unrestricted Cluster Security Groups

Description

Detects Amazon RDS database clusters that have security groups allowing unrestricted inbound access (0.0.0.0/0). This configuration could expose database instances to unnecessary risk by allowing access from any IP address on the internet.

Weakness:

109 - Unrestricted access between network segments - RDS

Category: Functionality Abuse

Detection Strategy

    Identifies all RDS clusters in the specified AWS region

    For each cluster, examines the attached VPC security groups

    Reports a vulnerability if any security group's inbound rules (IpPermissions) include the CIDR range 0.0.0.0/0

Severity v4.0

0.5

Low

Method ID

CSPM-EU9TU

Technique

CSPM

Target

AWS

Technology

RDS

CWE ID(s)

CWE-1327