ZeroDayAlert

CVE-2015-3306: ProFTPD Improper Access Control Vulnerability

ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

ProFTPD ProFTPD Added to KEV 2026-10-08 Federal due 2026-10-11 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

ProFTPD is affected by an improper access control vulnerability that allows remote attackers to read and write arbitrary files on a server. This affects deployments running ProFTPD where the site cpfr and site cpto commands are accessible. The record does not specify which versions of ProFTPD are vulnerable, nor does it indicate whether this affects only specific configurations.

How to check whether this touches you

  • Audit your inventory for any ProFTPD installations across on-premises and cloud environments, including development and staging systems.
  • Verify whether each ProFTPD instance is reachable from outside your network by checking firewall rules, network access control lists, and whether port 21 (FTP) or port 990 (FTPS) is exposed to the internet or untrusted networks.
  • Check the version of each running ProFTPD instance by connecting to the service and requesting its banner, or by examining installed package metadata; note that version numbers alone are not definitive proof of vulnerability status, as some distributions backport security patches.

What to do

  1. If you cannot patch immediately, restrict network access to ProFTPD by removing internet-facing routes to port 21/990 and limiting connections to trusted internal IP ranges only.
  2. Disable or restrict the site cpfr and site cpto commands in ProFTPD configuration if they are not required for your operations.
  3. Enable and review all available audit and access logs on your ProFTPD instances, paying particular attention to any use of site cpfr and site cpto commands; configure log retention to meet your forensic requirements.
  4. Apply patches or upgrades in accordance with ProFTPD vendor guidance and CISA BOD 26-04 timelines for your asset's risk profile and internet exposure.
  5. If no vendor mitigation is available and the product cannot be patched, evaluate whether discontinuing ProFTPD in favour of an alternative is feasible within your operational window.

If you find you were exposed

Exploitation of this vulnerability predates public disclosure, so you should search your FTP access logs backwards from the current date for any commands matching site cpfr or site cpto, particularly those followed by file read or write operations to sensitive paths. Log retention constraints mean many organisations will lack complete evidence; focus your hunt on the longest available log window and cross-reference suspicious FTP activity with filesystem change logs or integrity monitoring tools on the affected server.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2015-3306 is being exploited. It cannot tell you whether ProFTPD is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →