CVE-2026-5944
8.2Cisco · Intersight Device Connector for Nutanix Prism Central
An improper access control vulnerability in the Cisco Intersight Device Connector for Nutanix Prism Central allows unauthenticated network access to an API passthrough endpoint on TCP port 7373.
Executive summary
An unauthenticated access control vulnerability in the Cisco Intersight Device Connector for Nutanix Prism Central poses a significant risk to service availability by allowing unauthorized API interaction.
Vulnerability
This vulnerability stems from missing authentication for a critical API passthrough endpoint (CWE-306) and missing authorization (CWE-862) on TCP port 7373. An unauthenticated attacker with local network access can enumerate cluster metadata and invoke maintenance workflows, potentially causing service disruption.
Business impact
The vulnerability carries a CVSS score of 8.2, reflecting its potential to cause significant impact to system availability. While it does not facilitate credential theft or persistent configuration changes, an attacker can intentionally trigger maintenance workflows that result in the disruption of active workloads, leading to unplanned downtime and loss of service for business-critical applications.
Remediation
Immediate Action: Administrators must upgrade the Cisco Intersight Device Connector to version 7.5.1 or later via the Prism Central Life Cycle Manager (LCM) dashboard.
Proactive Monitoring: Security teams should monitor network traffic directed at TCP port 7373 for unauthorized connection attempts or anomalous API requests originating from untrusted internal network segments.
Compensating Controls: Implement network-level access control lists (ACLs) to restrict access to the Prism Central management interface and associated device connector endpoints to authorized administrative IP addresses only.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for service disruption and the ease of exploitation due to the unauthenticated nature of the API endpoint, this vulnerability should be treated with high priority. Organizations utilizing the affected Cisco Intersight Device Connector on Nutanix Prism Central must verify their version and apply the 7.5.1 update as soon as possible to prevent unauthorized service interference.
More Cisco CVEs
Sources
Originally found and disclosed by External Security Researcher (via Cisco), per the CVE Program record.