Database/Control plane, storage & DevOps
Cisco Intersight Device Connector for Nutanix Prism Central: The device connector exposes an unauthenticated API
Impact
The device connector exposes an unauthenticated API passthrough on TCP/7373 reachable within the deployment's network scope. An attacker with network access uses it to reach the Prism Central API without credentials - unauthenticated proxy into the virtualization control plane.
Who can reach it
Network access to TCP/7373 on the connector host. No authentication.
What to do
Apply the Nutanix fix per Security Advisory 0046 and restrict TCP/7373 with host or network firewall rules. The port restriction is the immediate control and can be applied before the software update.
References
Related entries
- OpenChoreo Backstage backend: hardcoded auth bypass exposes /api/* to unauthenticated callersCVE-2026-73666 · OpenChoreo Backstage backend (default auth policy)High
- HPE OneView: remotely exploitable session hijacking against the infrastructure management consoleCVE-2026-76718 · HPE OneView (web interface, session handling)High
- GitLab CE/EE: unsanitized Markdown JSON table content induces state-changing requests as a targeted userCVE-2026-78252 · GitLab CE/EE (Markdown JSON table renderer)High
- Ceph RGW (SigV4 signature verifier): Anyone handed a single presigned PUT URL gets more authority than whoever signedNCVD-2026-039-ceph-rgw-sigv4-signature-verifie · Ceph RGW (SigV4 signature verifier)High
- Ceph MON (config-key store, MMonSubscribe handler): MULTI-TENANT ISOLATION AND HOST COMPROMISE: one craftedNCVD-2026-041-ceph-mon-config-key-store-mmonsu · Ceph MON (config-key store, MMonSubscribe handler)High
- Ceph MON (ceph-mon): The monitor accepts pool create/delete and snapshot operations from any authenticated user thatCVE-2018-10861 · Ceph MON (ceph-mon)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.