Authenticated TLS + CVE Scan

The authenticated QROS platform lets you scan designated hosts with the full power of testssl.sh — the industry-standard TLS scanner — combined with our port/banner scanner and NVD CVE attribution. Every scan produces a detailed report with risk scores, priority bands, and remediation advice. The certificate is fetched first (Python stdlib ssl), so the report always has value even if testssl is slow — ideal for massive fleet inventories in a cybersecurity and quantum-readiness programme.

QROS · Scan · retail-bank.example.com:443job done
50quantum score
Retail banking · endpoint TLS
retail-bank.example.com
RSA-2048 · ShorTLS 1.2SHA-256HSTS on
RSA-2048 vulnerable to ShorPriority: Immediate
Data retention ≥10 years (transactions)HNDL +20
No PQC support in the TLS stack12 months
Migrate to Ed25519 / ML-DSA-65 hybridremediated

What the authenticated scan includes

Priority bands for remediation

Every finding is assigned a priority band:

What a QROS scan report looks like

The authenticated scan produces a detailed report with risk scores, findings by priority band, and remediation advice:

scanme.nmap.org (45.33.32.156) Risk: 98/100
TLS 1.0 enabledCritical

Disable TLS 1.0, enforce TLS 1.2+.

RSA-2048 keyHigh

Quantum-vulnerable. Plan PQC migration to ML-DSA.

OpenSSH 6.6.1Critical

5 CVEs (incl. CVE-2024-6387). Upgrade to 9.8p1.

HSTS not setMedium

Enable HSTS header: max-age=31536000.

2 Critical 1 High 1 Medium

FAQ

What does the authenticated scan include?

The authenticated scan includes a full testssl.sh TLS scan (protocols, ciphers, certificate chain), port + banner scan on 51 ports, NVD CVE attribution, composite risk score (0-100), priority bands, and remediation advice.

How is risk scored?

Risk is scored on a 0-100 scale based on algorithm strength (RSA-1024 = broken, RSA-2048 = quantum-vulnerable), key length (shorter = higher risk), protocol (TLS 1.0/1.1 = deprecated), and CVE severity (CVSS from the NVD).

Try this service with QROS

Explore now →