Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Operational Technology Vulnerability Response vulnerable item form fields

List of fields displayed in a vulnerable items created for OT devices.

Vulnerable item fields

FieldDescription
Overview
NumberAutomatically generated vulnerable item number for this record.
StateThis field defaults to Open, but you can change it to Under Investigation if the vulnerability is ready for immediate remediation.
Risk ratingQuantified Risk Score separating vulnerable items into Critical, High, Medium, Low, and None. For more information on risk ratings, see Vulnerability Response calculators and vulnerability calculator rules.Note: This base Risk rating isn’t the same as the Solution record Risk rating.
Risk score

Calculated amount of risk the vulnerable item poses to your environment.

Note: This base Risk score isn’t the same as the Solution record Risk score.

For more information, see Vulnerability Response calculators and vulnerability calculator rules.

VulnerabilityID of the vulnerability associated with this vulnerable item.
SourceScanner that found this vulnerable item.
Configuration itemID of the OT asset associated with this vulnerable item.
Assignment groupGroup selected to work on this remediation task.
Assigned toIndividual from the selected assignment group that works on this vulnerability.
CreatedDate this vulnerable item was created in your instance.
Last openedDate the vulnerable item was most recently opened in your instance. Initially, this is the same as the creation date of the vulnerable item, however, if it was closed, then reopened the Last opened date contains the date and time reopened.
UpdatedDate of the last scan.
SummaryDescription of the vulnerability.
SeverityNormalized degree of severity of this vulnerability. Severity maps are provided for NVD and with ServiceNow third-party integrations. For more information on creating or adjusting severity maps, see .Create a Vulnerability Response severity map.
Vulnerability score \(v3\)CVSS v3 score.
Vulnerability score \(v2\)CVSS v2 score.
Exploit existsYes, if at least one exploit is associated with the vulnerabilities associated with this vulnerable item.
Exploit attack vectorMost vulnerable attack vector of the exploits for the vulnerabilities associated with this vulnerable item.
Exploit skill levelLowest skill level required to exploit the vulnerabilities associated with this vulnerable item.
Date publishedDate the vulnerability was published.
Last modifiedDate the vulnerability was last modified.
ThreatRelevant information about the threat. Pulled from the vulnerable entry record.Note: Any changes made here update the vulnerable entry record.
Remediation notesRelevant solution to the threat, pulled from the vulnerable entry record.
Additional comments/Work notesAny relevant information. Select the check box to add Additional comments.Starting with Vulnerability Response v20.0, you can add work notes in the Notes section for a deferred vulnerable item.
ActivityOnly appears when a work note has been created.
Related Links
Calculate Risk ScoreWhen either the Vulnerability Severity or Risk Score calculators is enabled, the Risk Score field is updated.

Parent Topic:Operational Technology Vulnerability Response reference