Who is affected
ProFTPD is affected by an improper access control vulnerability that allows remote attackers to read and write arbitrary files on a server. This affects deployments running ProFTPD where the site cpfr and site cpto commands are accessible. The record does not specify which versions of ProFTPD are vulnerable, nor does it indicate whether this affects only specific configurations.
How to check whether this touches you
- Audit your inventory for any ProFTPD installations across on-premises and cloud environments, including development and staging systems.
- Verify whether each ProFTPD instance is reachable from outside your network by checking firewall rules, network access control lists, and whether port 21 (FTP) or port 990 (FTPS) is exposed to the internet or untrusted networks.
- Check the version of each running ProFTPD instance by connecting to the service and requesting its banner, or by examining installed package metadata; note that version numbers alone are not definitive proof of vulnerability status, as some distributions backport security patches.
What to do
- If you cannot patch immediately, restrict network access to ProFTPD by removing internet-facing routes to port 21/990 and limiting connections to trusted internal IP ranges only.
- Disable or restrict the site cpfr and site cpto commands in ProFTPD configuration if they are not required for your operations.
- Enable and review all available audit and access logs on your ProFTPD instances, paying particular attention to any use of site cpfr and site cpto commands; configure log retention to meet your forensic requirements.
- Apply patches or upgrades in accordance with ProFTPD vendor guidance and CISA BOD 26-04 timelines for your asset's risk profile and internet exposure.
- If no vendor mitigation is available and the product cannot be patched, evaluate whether discontinuing ProFTPD in favour of an alternative is feasible within your operational window.
If you find you were exposed
Exploitation of this vulnerability predates public disclosure, so you should search your FTP access logs backwards from the current date for any commands matching site cpfr or site cpto, particularly those followed by file read or write operations to sensitive paths. Log retention constraints mean many organisations will lack complete evidence; focus your hunt on the longest available log window and cross-reference suspicious FTP activity with filesystem change logs or integrity monitoring tools on the affected server.