Glossary
CPE (Common Platform Enumeration)
A standardized naming scheme for identifying software, hardware and operating systems, e.g. cpe:/a:openbsd:openssh:7.4 — how Nmap and vulnerability databases refer to the same product unambiguously.
CPE (Common Platform Enumeration) is a structured naming scheme for identifying a specific piece of software, hardware or an operating system, maintained by NIST. A CPE string looks like:
cpe:/a:openbsd:openssh:7.4
Read left to right: a means "application" (o is operating system, h is
hardware), then vendor (openbsd), product (openssh), and version (7.4).
Why Nmap reports it
When Nmap's service detection (-sV) identifies a service with enough
confidence, it attaches a CPE to the <service> element in its XML output.
This matters because CPEs are the same identifiers vulnerability databases
(including the NVD) use to tag which products a CVE
affects — a CPE is a more precise, less ambiguous key to match against than
a free-text "product + version" string, which can vary in formatting between
tools.