Skip to main content
compliance · aws

Security groups open to 0.0.0.0/0 on admin or database ports

resource types
1
rule IDs covered
1
severity
critical

What does ZopNight detect here?

ZopNight flags an EC2 security group with an inbound rule from `0.0.0.0/0` or `::/0` to a sensitive port (22, 3389, 3306, 5432, 1433, 27017, 6379 or 9200) or to every port. Port ranges are checked for any sensitive port inside them, so a wide range cannot hide SSH. Public 443 alone is not flagged. The finding carries a $0 saving.

Signal and threshold

How ZopNight evaluates Security groups open to 0.0.0.0/0 on admin or database ports.
Field Value
Rule IDsRC-084
Categorycompliance
Severitycritical
Metricnone — pure configuration read
Threshold0.0.0.0/0 to a sensitive port
SourceZopNight
Permissions usedec2:DescribeSecurityGroups · ec2:DescribeSecurityGroupRules

Why these ports should never face the whole internet

A security group rule with source 0.0.0.0/0 accepts traffic from every IPv4 address. That is the intended setting for a load balancer on 80 or 443, as the security group rules guide shows. It is a serious exposure for anything else. Automated scanners sweep the public IPv4 space continuously, and the ports below expose admin and data services.

PortUsual service
22SSH
3389Remote Desktop
3306MySQL and MariaDB
5432PostgreSQL
1433SQL Server
27017MongoDB
6379Redis
9200Elasticsearch and OpenSearch

Listing world-open rules

Find groups with any rule from 0.0.0.0/0, then list the individual inbound rules of one group:

Terminal window
aws ec2 describe-security-groups \
--filters Name=ip-permission.cidr,Values=0.0.0.0/0 \
--query 'SecurityGroups[].[GroupId,GroupName]' --output table
aws ec2 describe-security-group-rules \
--filters Name=group-id,Values=sg-0123456789abcdef0 \
--query 'SecurityGroupRules[?!IsEgress && CidrIpv4==`0.0.0.0/0`].[SecurityGroupRuleId,IpProtocol,FromPort,ToPort]'

An IpProtocol of -1 means all protocols and ports.

Rules that trigger a finding

ZopNight reads every inbound rule of each security group and records which ports are open to 0.0.0.0/0 or ::/0. A finding is raised when either is true:

  1. A public rule covers all ports, written as 0 to 65535 or as protocol -1.
  2. A public rule reaches one of the eight sensitive ports, including a sensitive port that sits inside a wider range such as 1 to 10000.

What does not trigger it

Public rules that only open other ports, such as 443 for HTTPS, are not flagged. Rules whose source is a specific CIDR or another security group are not flagged either. If ZopNight could not read the group’s rules, it records no ports and raises nothing. For databases, the related RDS Instance Publicly Accessible check looks at the instance side.

The cost of leaving it open

The finding saves nothing. Its severity is critical because an open admin or database port turns a weak password or an unpatched service into a direct compromise.

Closing the rule safely

  1. Work out who needs the port. Replace 0.0.0.0/0 with your office or VPN CIDR, or with the security group of the calling tier.
  2. For SSH and RDP, use Session Manager, which works without open inbound ports, bastion hosts or SSH keys.
  3. Remove the public rule:
Terminal window
aws ec2 revoke-security-group-ingress --group-id sg-0123456789abcdef0 \
--security-group-rule-ids sgr-0123456789abcdef0
  1. Remove any matching rule with an IPv6 source of ::/0 too; ZopNight treats it the same way.
  2. Move databases and caches into private subnets so a future rule change cannot expose them.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·