WithSecure Repository: Threat Intelligence

Permissive Cloud Network Connectivity

This misconfiguration highlights a detailed aspect of the MITRE ATT&CK matrix and describes a security gap with overly permissive network connectivity in a cloud environment.


Overly permissive network connectivity in cloud environments poses significant security risks by allowing unrestricted access to resources. This can lead to unauthorized access, data breaches, and lateral movement by attackers within the network. Such permissive configurations often result from misconfigured firewall rules or overly broad network security group settings.


Mitigation: To mitigate these risks, it's crucial to implement strict access controls, regularly audit network configurations, and employ tools that provide visibility and insights into network traffic patterns. By tightening network policies, organizations can reduce their attack surface and enhance overall cloud security.



ID: WITH-SM-6
Domain: withsecure-security-misconfiguration
Version: 1.0