Database/Control plane, storage & DevOps
Cisco Intersight Device Connector for Nutanix Prism Central: The device connector exposes an unauthenticated API
Impact
The device connector exposes an unauthenticated API passthrough on TCP/7373 reachable within the deployment's network scope. An attacker with network access uses it to reach the Prism Central API without credentials - unauthenticated proxy into the virtualization control plane.
Who can reach it
Network access to TCP/7373 on the connector host. No authentication.
What to do
Apply the Nutanix fix per Security Advisory 0046 and restrict TCP/7373 with host or network firewall rules. The port restriction is the immediate control and can be applied before the software update.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.