GPU VulnDB

Database/Control plane, storage & DevOps

Cisco Intersight Device Connector for Nutanix Prism Central: The device connector exposes an unauthenticated API

CVE-2026-5944Control plane, storage & DevOpscurated

Impact

The device connector exposes an unauthenticated API passthrough on TCP/7373 reachable within the deployment's network scope. An attacker with network access uses it to reach the Prism Central API without credentials - unauthenticated proxy into the virtualization control plane.

Who can reach it

Network access to TCP/7373 on the connector host. No authentication.

What to do

Apply the Nutanix fix per Security Advisory 0046 and restrict TCP/7373 with host or network firewall rules. The port restriction is the immediate control and can be applied before the software update.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.