CVE-2026-5944

MEDIUM EPSS 40.9%
Published Apr 28, 20262mo ago · Modified Jun 17, 20261w ago
6.7 CVSS 4.0
Medium
Find Similar
Published Apr 28, 2026 2mo ago
Last Modified Jun 17, 2026 1w ago

Description

An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment without authentication. An unauthenticated attacker with network access can exploit this vulnerability by sending crafted requests to the exposed endpoint to enumerate cluster metadata, including virtual machine information and cluster configuration details. While the API primarily supports read-only operations, it also allows certain cluster maintenance workflows to be invoked. Although this vulnerability does not allow persistent modification of system configurations or access to credentials or sensitive user data, successful exploitation may result in disruption of active workloads, leading to loss of service availability within the affected environment.

CVSS Details

Base Score
6.7
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:L/U:Amber
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope N

Threat Intelligence

EPSS Exploit Probability
40.9% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 2

CWE-306 Missing Authentication for Critical Function Authentication
CWE-862 Missing Authorization Authorization

Affected Products 1

VendorProductVersionRange
ciscointersight_device_connector*≥4.3.0  –  ≤7.5.0

References 3

  • download.nutanix.com https://download.nutanix.com/alerts/Security_Advisory_0046.pdf
    Third Party Advisory
  • portal.nutanix.com https://portal.nutanix.com/page/documents/list?type=software&filterKey=software&filterVal=Prism
    ProductThird Party Advisory
  • nutanix.com https://www.nutanix.com/support
    ProductThird Party Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.