MEDIUM
Source
CloudSploit
ID
open-vnc-client

Open VNC Client

Ensure that security groups does not have TCP port 5500 for VNC Client open to the public.

While some ports such as HTTP and HTTPS are required to be open to the public to function properly, more sensitive services such as VNC Client should be restricted to known IP addresses.

Restrict TCP port 5500 to known IP addresses