Skip to content

How to read an Nmap scan for vulnerabilities and misconfigurations

A practical walkthrough of what to look for in Nmap output — service versions worth checking against CVEs, and the misconfigurations that show up again and again.

Published on 3 min read

An Nmap scan gives you a lot more than "which ports are open." With service detection and the right scripts enabled, a single scan surfaces most of what you need to triage a host: what's running, how old it is, and whether it's misconfigured in one of a handful of well-known ways.

Run it with enough detail

The default nmap <target> only tells you which ports are open. To get anything actionable, add:

nmap -sV -O --script vuln,ftp-anon,vulners -oX scan.xml <target>
  • -sV — service/version detection. Without this, you only get a port number and a guessed service name, not a version string to check against anything.
  • -O — OS detection.
  • --script vuln — runs every NSE script in the vuln category: active checks for specific, named vulnerabilities (EternalBlue, Heartbleed, DROWN, and dozens more).
  • --script vulners — looks up detected product/versions against a CVE dataset and lists every match with a CVSS score.
  • -oX scan.xml — XML output. It's the richest format (clean product/version fields, CPEs, full script output structured per port), so anything that parses Nmap output — including this tool — gets the most out of it.

What to look for in the output

Service versions. A line like Apache httpd 2.4.49 is a direct lead: search "Apache 2.4.49 CVE" or run it through a vuln matcher. Old, specific version numbers (not just "Apache 2") are what make this useful — vague banners mean you'll need an NSE probe instead.

Script output that says VULNERABLE. If you ran --script vuln, any script output containing a State: VULNERABLE line is Nmap telling you, directly, that the target matches a known-bad condition — not a guess from a version string.

Anonymous/unauthenticated access. A handful of services get checked for this specifically and show up constantly in the wild:

  • ftp-anon — anonymous FTP login allowed.
  • redis-info returning data — Redis reachable without a password.
  • mongodb-databases/mongodb-info returning data — same, for MongoDB.
  • SMB null sessions — anonymous enumeration of shares/users.

Legacy protocols. Telnet, FTP, and SMBv1 all show up far more often than they should. None of them are a specific CVE — they're a design-level weakness (cleartext credentials, or, for SMBv1, the dialect EternalBlue targets) worth flagging regardless of patch level.

Default/placeholder pages. An http-title of "Apache2 Ubuntu Default Page" or "Welcome to nginx!" usually means a box that was provisioned and never finished — worth a second look at what else is running on it.

Where this tool fits

Pasting (or uploading) that same -oX output here does the version lookups and script-output parsing above automatically, across every host in the scan, and lays the hosts out as a map so you can see exposure at a glance instead of reading line by line.