Property
Languagehcl
Severitymedium
CWECWE-284: Improper Access Control
OWASPA01:2021 - Broken Access Control
Confidence LevelLow
Impact LevelMedium
Likelihood LevelMedium

Description#

This code configures a network ACL rule in AWS to allow incoming traffic from any public IP address. Allowing unrestricted public ingress exposes your resources to the entire internet, increasing the risk of unauthorized access.

Impact#

If exploited, attackers could access or probe your AWS resources from anywhere on the internet, potentially leading to data breaches, service disruptions, or unauthorized use of your cloud infrastructure. This exposure makes your environment a target for automated attacks and malicious actors.