Gimmal's vulnerability footprint centers on its Sherpa Connector Service, a modestly represented product line with a focused attack surface. The observed signal clusters around unquoted search-path handling, a legacy file-system execution vulnerability characteristic of Windows service configurations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gimmal over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23909HIGH There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C: | Apr 5, 2022 | 7.8 | 37 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gimmal.
Media articles that mention a CVE ID that affects a product developed by Gimmal — matched by CVE ID, not by vendor name.