Find out which devices a new CVE actually reaches
NacTrack matches published CVEs against the versions you have installed, not against a vendor family. It flags end of support the same way.
Why the exact version changes everything
A vulnerability does not affect a model, it affects specific software versions of a model. Without the exact version you patch what does not need it and miss what matters.
NacTrack knows the version because it read it off the device. Matching against the catalogue becomes mechanical, and the list of affected devices is by name.
- Matched by version, not by model
- Severity, known exploitation, likelihood
- The fixing version named
- Catalogue updatable offline
- Export for a security committee
From the software read to the named finding
The link that decides everything is the second. Matching on the model instead of the version names devices that are not affected and misses ones that are.
READ FROM
- Devicewhat is running
- Exact versionnot the planned one
- Normalised platformone vocabulary
- Cataloguepublished continuously
- Findingon this device
The catalogue transfers by file on an installation with no internet access: this link does not depend on a permanent connection.
End of support, the other missing inventory
- A device past support does not fail on the announcement date. It becomes unrepairable.
- You find out on the day it fails: the part no longer exists, the contract no longer covers it.
- No fix will ship for the next vulnerability that reaches it.
- NacTrack keeps an end of sale and end of support catalogue per model and matches it against the real estate.
- The result is a dated list, usable to build a replacement plan and to defend it in budget.
- It is the information most often missing at audit, because producing it requires a current inventory.
Hardware lifecycle has a page of its own: the five states, the at risk window, and what the catalogue does not cover.

