In our 35-person textile wholesale company, we set up an on-premise Linux server hosting our in-house order and customer database. We only give external access through specific ports on a limited basis. To test its security, I ran two popular open-source automated pentest and vulnerability scanning tools against the server.
When the report finished, the screen was completely red; the tools listed over 140 warnings in total, including 12 "critical" and "high" severity vulnerabilities. When our company manager saw the report he got worried enough to consider shutting down the entire system. But when I looked at the details, some items seemed way too generic to me; for example, there are warnings that just read the software version number and assume it's outdated.
How should we filter the results produced by these kinds of automated pentest tools? Which ones are real attack vectors, and which ones are just informational noise? Is there a sensible elimination method we should follow before panicking and touching everything?