Skip to main content

VPC Route Table Has Excessive Privileges

Overview​

In cloud networking the best practice is to create a Minimum Viable Network that consists only of the routes and security group rules to support application/project functionality. This typically means very tightly scoped route tables and security groups. This check looks for route tables that may enable overly-wide access, which could indicate a network with a wider blast radius that is more-susceptible to damaging network-based attacks.

Vendor​

AWS

Cloud Service​

EC2

CSMM v1 NET-04.2

Severity​

2

Item Types​

AWS::EC2::VpcPeeringConnection