---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Identifying duplicate vulnerable items from multiple scanners

# Identifying duplicate vulnerable items from multiple scanners {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

If you are using multiple scanners on the same asset to detect vulnerabilities, multiple
vulnerable items (VIs) might be created. You can identify these duplicate VIs to ensure that the
duplicate vulnerabilities are not assigned to the remediation owners.

This resolution is possible only if the same vulnerabilities, such as the same Common
Vulnerabilities and Exposures (CVEs) are detected. The vulnerability combination depends on the
scanners being used. For example, Qualys and Tenable have their own vulnerability type, that is,
third-party entries (TPEs), and other scanners such as Microsoft Defender for Endpoint detect
vulnerabilities based on CVEs.

Starting from v 17.1, while creating a remediation effort, you can
automatically refresh duplicate vulnerable items on the created remediation tasks. To
automatically refresh the duplicate vulnerable items, you must select the
Automatically refresh duplicate vulnerable items for the created remediation tasks option.

Show Duplicate VIs: Identify duplicate vulnerable items reported by
multiple scanners in the system. You can mark the duplicate VI as Resolved. For more information, see [Automatically resolve duplicate vulnerabilities](https://servicenow-prod.fluidtopics.net/~JCWwgntx7i04vJ3uZhr9w "Starting from Vulnerability Response (VR) v17.1, you can automatically resolve any duplicate vulnerabilities on an asset."). Duplicate entries are only shown when the combination of vulnerabilities
is created using CVEs. For more information, see Vulnerability Response remediation task and
vulnerable item states.  
Potential duplicates are identified for the following vulnerability combinations:{#correlate-vis-from-diff-scanners__table_wyq_2l5_d5b__entry__2}

| Scanner combination | Type of vulnerability |
|-|-|
| Scanner 1 and Scanner 2 | CVE |
| Scanner 1 and Scanner 2 | CVE and TPE |
[ ]

{#correlate-vis-from-diff-scanners__table_wyq_2l5_d5b}

