Steps to block endpoint setupmgr.cgi and setup in NCM
Environment
NCM 10.1.x
Cause
Not secured
Unauthorized users can perform operations on it without needing to log in to the service.
The UI presented after launching the endpoint suggests that operations performed on it could lead to data leakage (e.g., transferring a copy of the database to a specified FTP/TFTP server) or even the uninstallation of NCM itself.
Resolution
Follow below steps to disable the endpoint https://<NCM>:443/setup
Delete below directory
rm -rf $VOYENCE_HOME/ui/html/setup
Restart vcmaster service
service vcmaster restart
Follow below steps to disable the endpoint https://<NCM>:443/setupmgr.cgi