IPv6 can create exposure beside an IPv4 mental model

Many systems have IPv6 enabled and reachable while everybody's mental model, and sometimes the firewall rules, cover only IPv4.

The result is a second front door nobody is looking at, often with no equivalent filtering. It is not exotic; it is default on most modern operating systems. The check is simple and rarely done: is this reachable over IPv6, and do the same rules apply.

More on Attack surface management