I don't believe you. I'm willing to listen though. Do you have a link to a detailed, technical explanation of this?
I have a computer running services A and B and several computers running service B. Service A exposes information about the computer's configuration that helps attack service B, but only if the attacker can figure out which one.
Edit: I haven't really been able to find a comparison between firewalling and firewalling+NAT, just comparisons between nothing and NAT.
My scenario is narrow, but I expect it to be a common one: IPv6 internet boxes will likely include such a firewall by default.
If we can believe the old adage that "The only secure server is one encased in concrete", then the average non-NATTED device is more akin to one that is concreted than one with public addressability.