Property
Languageterraform
Severitycritical
Servicenetwork
ProviderAzure
Vulnerability Typemisconfiguration

Description#

The network security group allows inbound SSH (port 22) connections from any IP address, exposing SSH access to the entire internet. This configuration makes remote server management interfaces publicly accessible and highly susceptible to unauthorized access attempts.

Impact#

Unrestricted internet access to SSH can enable attackers to attempt brute-force attacks, exploit vulnerabilities, or gain unauthorized control over cloud resources. This may lead to data breaches, service disruption, or further compromise of the organization’s Azure environment.

Resolution#

Block port 22 access from the internet