HIGH
Source
CloudSploit
ID
open-sql-server

Open SQL Server

Ensure that security groups does not have TCP port 1433 or UDP port 1434 for SQL Server open to the public.

While some ports such as HTTP and HTTPS are required to be open to the public to function properly, more sensitive services such as SQL Server should be restricted to known IP addresses.

Restrict TCP port 1433 or UDP port 1434 for SQL Server to known IP addresses