Skip to main content

VPC Route Table Has Excessive Privileges

Overview

In cloud networking the best practice is to create a Minimum Viable Network that consists only of the routes and security group rules to support application/project functionality. This typically means very tightly scoped route tables and security groups. This check looks for route tables that may enable overly-wide access, which could indicate a network with a wider blast radius that is more-susceptible to damaging network-based attacks.

Vendor

AWS

Cloud Service

EC2

CSMM v1 NET-04.2

Severity

2

Item Types

AWS::EC2::VpcPeeringConnection