Severity: High
Internet-facing SSH jump box
- Observation
- The SSH service on a jump box answered a connection from an outside address. It is reachable from the entire internet, not just from the office or the VPN.
- Criteria
- NIST SP 800-53 AC-17 (Remote Access), HIPAA §164.312(a)(1) (Access Control), and HITRUST Domain 08 (Network Protection).
- Impact
- Malicious actors from the entire internet can attempt to brute force their way into the jump box as a way of gaining initial entry into the data environment. Even if password authentication is disabled, vulnerabilities in the SSH service like CVE-2024-6387 and CVE-2024-6409 can still allow remote code execution from any source.
- Recommendation
- Measure who and what is legitimately interacting with the jump box. Restrict access to known IP ranges. If unrestricted public access has to remain, conduct a risk analysis to identify mitigating controls and record an exception in the company's risk register.