How to read an Nmap scan for vulnerabilities and misconfigurations
A practical walkthrough of what to look for in Nmap output — service versions worth checking against CVEs, and the misconfigurations that show up again and again.
An Nmap scan gives you a lot more than "which ports are open." With service detection and the right scripts enabled, a single scan surfaces most of what you need to triage a host: what's running, how old it is, and whether it's misconfigured in one of a handful of well-known ways.
Run it with enough detail
The default nmap <target> only tells you which ports are open. To get
anything actionable, add:
nmap -sV -O --script vuln,ftp-anon,vulners -oX scan.xml <target>
-sV— service/version detection. Without this, you only get a port number and a guessed service name, not a version string to check against anything.-O— OS detection.--script vuln— runs every NSE script in thevulncategory: active checks for specific, named vulnerabilities (EternalBlue, Heartbleed, DROWN, and dozens more).--script vulners— looks up detected product/versions against a CVE dataset and lists every match with a CVSS score.-oX scan.xml— XML output. It's the richest format (clean product/version fields, CPEs, full script output structured per port), so anything that parses Nmap output — including this tool — gets the most out of it.
What to look for in the output
Service versions. A line like Apache httpd 2.4.49 is a direct lead:
search "Apache 2.4.49 CVE" or run it through a vuln matcher. Old, specific
version numbers (not just "Apache 2") are what make this useful — vague
banners mean you'll need an NSE probe instead.
Script output that says VULNERABLE. If you ran --script vuln, any
script output containing a State: VULNERABLE line is Nmap telling you,
directly, that the target matches a known-bad condition — not a guess from a
version string.
Anonymous/unauthenticated access. A handful of services get checked for this specifically and show up constantly in the wild:
ftp-anon— anonymous FTP login allowed.redis-inforeturning data — Redis reachable without a password.mongodb-databases/mongodb-inforeturning data — same, for MongoDB.- SMB null sessions — anonymous enumeration of shares/users.
Legacy protocols. Telnet, FTP, and SMBv1 all show up far more often than they should. None of them are a specific CVE — they're a design-level weakness (cleartext credentials, or, for SMBv1, the dialect EternalBlue targets) worth flagging regardless of patch level.
Default/placeholder pages. An http-title of "Apache2 Ubuntu Default
Page" or "Welcome to nginx!" usually means a box that was provisioned and
never finished — worth a second look at what else is running on it.
Where this tool fits
Pasting (or uploading) that same -oX output here does the version lookups
and script-output parsing above automatically, across every host in the
scan, and lays the hosts out as a map so you can see exposure at a glance
instead of reading line by line.