AWS-VPC-SG-allow-ingress-from-all-source-to-port-3389
Severity: High
Description: This controls ensures that no security allows ingress from 0.0.0.0/0 to port 3389. Security groups provide stateful filtering ingress/egress network traffic to AWS resources. It is recommended that no security group allows unrestricted ingress access to port 3389.
Remediation Steps:
Perform following to update DocumentDB master user name:
Login to the AWS Management Console at https://console.aws.amazon.com.
Navigate to VPC console.
In the left pane, click Security Groups.
Select the security group reported.
Click the Inbound Rules tab.
Click Edit rules.
Identify the rules to be removed.
Click the x in the Remove column.
Click Save rules.
Important:
Remediation may result in user losing RDP access, whose IP is not whitelisted in rules.
Reference:
CIS reference: CIS Amazon Web Services Foundations Benchmark v1.3.0 - 08-07-2020: Recommendation #5.2 (check 2)
Â
Blue Hexagon Proprietary