Definition · Known Vulnerabilities (CVEs)
What is CPE?
CPE (Common Platform Enumeration) gives software and hardware a machine-readable name so that tools can say, unambiguously, which product a vulnerability applies to. It is maintained as part of NIST’s Security Content Automation Protocol work and is used throughout the NVD to attach affected-product data to CVE records.
Anatomy of a CPE name
The current format is CPE 2.3, written as a colon-delimited formatted string:
cpe:2.3:a:apache:http_server:2.4.57:*:*:*:*:*:*:*
The fields are, in order: the cpe prefix and version, the part (a for application, o for operating system, h for hardware), vendor, product, version, update, edition, language, and four further target and edition qualifiers. An asterisk means “any” and a hyphen means “not applicable”.
Why CPE matters for external scanning
Matching a detected service to a CVE list is only as good as the product identification behind it. Service fingerprinting and banner grabbing produce a vendor, product, and version guess; CPE is the vocabulary that turns that guess into a lookup against vulnerability data.
Known limitations
CPE naming is inconsistent in practice. The same product can appear under different vendor strings across years of records, version ranges are sometimes expressed loosely, and a CVE record may list no CPE data at all. This is a common source of both false positives and missed findings in version-based matching, which is why detection that actively confirms a condition — as Nuclei templates do — is a useful complement.
Related concepts
CPE sits alongside CVE (which flaw) and CWE (what class of weakness) in the NVD’s data model, and underpins the inventory matching that vulnerability management depends on.