logo

Database

Aws Allow All Egress

Description

Detects AWS Network Access Control Lists (NACLs) that have overly permissive outbound rules allowing unrestricted egress traffic. Unrestricted outbound access could enable compromised resources to exfiltrate data or communicate with malicious actors.

Detection Strategy

    Examines each Network ACL's outbound rules in the specified AWS region

    Reports a vulnerability if a NACL rule allows outbound traffic (egress) to all destinations (0.0.0.0/0)

    Evaluates all Network ACLs associated with VPCs in the account for compliance with egress traffic restrictions

Severity v4.0

1.7

Low

Method ID

CSPM-EWCRF

Technique

CSPM

Target

AWS

Technology

EC2

CWE ID(s)

CWE-1327