This is legit, I've been communicating with a number of people at CERT Vulnerability Notes Database to acknowledge and to backfill the information. It's not public yet, as far as I can tell in VINCE.
The issue has been reported privately and is fixed in firmware build 2.4.2.157: Release 2.4.2 Available - #10 by gopher.ny.
In a nutshell, if you have a functioning link to a single dashboard, you can use some crafty ways to access other dashboards and to control devices that the original dashboard has no permissions to.