PT-2026-35723 · Cisco · Intersight Device Connector For Nutanix Prism Central
Published
2026-04-28
·
Updated
2026-05-18
·
CVE-2026-5944
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Intersight Device Connector for Nutanix Prism Central (affected versions not specified)
Description
An improper access control issue exists where a service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the deployment environment's network scope without authentication. An unauthenticated attacker can send crafted requests to this endpoint to enumerate cluster metadata, such as virtual machine information and cluster configuration details. Although the API mainly supports read-only operations, it allows the invocation of certain cluster maintenance workflows. Successful exploitation could disrupt active workloads, resulting in a loss of service availability, though it does not permit persistent configuration changes or access to credentials and sensitive user data.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Intersight Device Connector For Nutanix Prism Central