They are goldmine of enumerated attack surface. But it would likely require some kind of secondary exploit of the identified vulns. The API connections are generally scoped to read-only access of security settings. Though it wouldn't surprise me if there was some way to get lateral movement from the access these tools have to monitor an environment.