A vulnerability scanner is a tool that inspects systems, networks or applications to identify known security weaknesses. It compares discovered software and configurations against databases of disclosed vulnerabilities.
Semantic Classification
Content
- A vulnerability scanner probes hosts, networks or code to detect security weaknesses, then matches findings against catalogues of known vulnerabilities such as the CVE list. Scanners may perform unauthenticated network checks or authenticated inspection of installed software and configurations.
- Outputs typically include severity ratings and remediation guidance that feed patch management and risk prioritisation. Scanning complements deeper manual work such as penetration testing within an organisation’s security programme.