Skip to content

Glossary

CPE (Common Platform Enumeration)

A standardized naming scheme for identifying software, hardware and operating systems, e.g. cpe:/a:openbsd:openssh:7.4 — how Nmap and vulnerability databases refer to the same product unambiguously.

CPE (Common Platform Enumeration) is a structured naming scheme for identifying a specific piece of software, hardware or an operating system, maintained by NIST. A CPE string looks like:

cpe:/a:openbsd:openssh:7.4

Read left to right: a means "application" (o is operating system, h is hardware), then vendor (openbsd), product (openssh), and version (7.4).

Why Nmap reports it

When Nmap's service detection (-sV) identifies a service with enough confidence, it attaches a CPE to the <service> element in its XML output. This matters because CPEs are the same identifiers vulnerability databases (including the NVD) use to tag which products a CVE affects — a CPE is a more precise, less ambiguous key to match against than a free-text "product + version" string, which can vary in formatting between tools.