---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Exposure assessment by CVE

# Exposure assessment by CVE {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Exposure assessment uses Common Vulnerabilities and Exposures (CVEs) to assess the exposure of your assets using the software discovery model. You can use the exposure assessment by CVE to identify exposure to potential
vulnerabilities.

For information on assessing exposure by CVE, see:

* [Add CVEs to assess exposure](https://servicenow-prod.fluidtopics.net/m8_tpeVH2yrHq9FY2FKyjQ "Add Common Vulnerabilities and Exposures (CVEs) to the exposure configuration list of CVEs in Exposure Assessment to assess the impact of a new vulnerability or zero-day vulnerability.")
* [Create VIs for CVEs for exposure assessment](https://servicenow-prod.fluidtopics.net/kajGo5FzBjPEe080nNZvOA "Create vulnerable items (VIs) from the Exposure Assessment page. Vulnerability event managers then analyze this list of VIs and recommend solutions and patches that help the IT team to patch these vulnerabilities.")
* [Activate or deactivate CVEs for exposure assessment](https://servicenow-prod.fluidtopics.net/M5iHJPBJyn2qhZ8BPoaVrA "For delta processing of a CVE, you can activate it, thus adding it to the active list of CVEs.")
* [Export impacted CIs for exposure assessment](https://servicenow-prod.fluidtopics.net/PMtlBdPeZqDRD8BZ8S_aaQ "You can track the impacted assets list for a new CVE by exporting the configuration items (CIs) related to an exposure assessment record to an excel sheet. This sheet can be used to share the assets details and owners to create incidents with the known impacted assets for the zero-day vulnerabilities.")
* [Confidence score calculation example](https://servicenow-prod.fluidtopics.net/DcjdpOMVF1jxLPGECoBC5Q "Example of calculating the confidence for a zero-day vulnerability based on its Common Vulnerabilities and Exposures (CVE) information.")
{#vr-ws-exposure-assessment-cve__ul_fcq_pd4_dyb}

