Skip to content

Azure network_udp_internet_access_restricted misses NSG rules with protocol Any (*), reporting a false negative #12885

Description

@pouria-l

Issue search

  • I have searched the existing issues and this bug has not been reported yet

Which component is affected?

Prowler CLI/SDK

Cloud Provider (if applicable)

Azure

Steps to Reproduce

  1. Create an NSG with one inbound rule that allows Any protocol from the Internet:
az network nsg create --resource-group <rg> --name nsg-udp-any
az network nsg rule create --resource-group <rg> --nsg-name nsg-udp-any \
  --name any-from-internet --priority 100 --direction Inbound --access Allow \
  --protocol '*' --source-address-prefixes Internet --destination-port-ranges '*'

Azure stores the rule with "protocol": "*" and "sourceAddressPrefix": "Internet".

  1. Run the check:
prowler azure --az-cli-auth --azure-resource-group <rg> --check network_udp_internet_access_restricted

For comparison, an otherwise identical rule with --protocol Udp is correctly reported as FAIL.

Expected behavior

FAIL. A rule with protocol Any (*) allows UDP, so every UDP port on the resources behind the NSG is reachable from the Internet.

Actual Result with Screenshots or Logs

PASS: "Security Group nsg-udp-any ... has UDP internet access restricted."

The fail condition only accepts "UDP" and "Udp":

rule.protocol in ["UDP", "Udp"]

https://github.com/prowler-cloud/prowler/blob/master/prowler/providers/azure/services/network/network_udp_internet_access_restricted/network_udp_internet_access_restricted.py#L21

The SSH, RDP and HTTP checks in the same service already treat * as matching TCP (["TCP", "Tcp", "*"]), so the UDP check is the only one of the four that misses it.

How did you install Prowler?

Cloning the repository from github.com (git clone)

Environment Resource

Workstation

OS used

MacOS

Prowler version

5.40.0 (the affected line is unchanged on current master)

Python version

3.13.8

Pip version

N/A (uv-managed virtualenv)

Context

This is separate from #12854 and its PR #12866. Those cover the destination port condition in the SSH, RDP and HTTP checks. This bug is in the protocol condition of the UDP check, which #12866 does not touch, so the two fixes do not overlap.

I have a fix with a test ready and will open a PR shortly.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions