CISA has added CVE-2015-3306 to its Known Exploited Vulnerabilities catalog, confirming active exploitation. The flaw is a decade-old access control bug in ProFTPD 1.3.5 that lets remote attackers read and write arbitrary files.
What Is It
CVE-2015-3306 is an improper access control vulnerability (CWE-284) in the mod_copy module of ProFTPD 1.3.5. According to NVD, remote attackers can use the site cpfr and site cpto commands to read and write arbitrary files. NVD first published the CVE on May 18, 2015.
Why It Matters
CISA added the flaw to the KEV catalog on 2026-10-08, which confirms it is being actively exploited. CISA's SSVC assessment also lists exploitation as active and technical impact as total.
- CVSS 3.1: 10.0 (Critical). The vector is
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Attackers can exploit it over the network with low complexity, and it needs no privileges or user interaction. - CVSS 2.0: 10.0, with complete confidentiality, integrity and availability impact.
- Public exploits: NVD references Exploit-DB entries 36742 and 36803. It also references several Packet Storm postings, including a CPFR/CPTO proof-of-concept and "Remote Command Execution" exploits, plus a Rapid7 Metasploit module (
proftpd_modcopy_exec). - Ransomware use: KEV lists known ransomware campaign use as "Unknown."
- Forensic triage: KEV flags this entry "Yes" for forensic triage, which means CISA's Forensics Triage Requirements apply.
What's Vulnerable
- ProFTPD 1.3.5 (
cpe:2.3:a:proftpd:proftpd:1.3.5) with themod_copymodule
CISA notes that the flaw could affect an open-source component, third-party library, protocol or proprietary implementation used by other products. Downstream products that embed ProFTPD may also be exposed.
Patch Status
CISA's required action is to apply mitigations according to vendor instructions. The KEV entry points to BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. BOD 26-04 binds federal civilian executive branch agencies. Other organizations can use it as guidance. If no mitigations are available, CISA's listed action is to follow BOD 26-04 guidance for cloud services or stop using the product. CISA also recommends evaluating each asset's internet exposure. The federal due date is 2026-10-11.
Debian (DSA-3263), Fedora and openSUSE published distribution advisories in 2015. Check your distribution's package status and the vendor's guidance at proftpd.org.
Sources
- CISA KEV Catalog: CVE-2015-3306
- NVD: CVE-2015-3306
- CISA BOD 26-04
- CISA BOD 26-04 Implementation Guidance (Forensics Triage)
- ProFTPD Project
- Debian DSA-3263
- Debian Security Announcement
- Fedora Package Announcement (157053)
- Fedora Package Announcement (157054)
- Fedora Package Announcement (157581)
- openSUSE Update Advisory
- Rapid7 Metasploit Module: proftpd_modcopy_exec
- Exploit-DB 36742
- Exploit-DB 36803
- Packet Storm: ProFTPd CPFR/CPTO Proof of Concept
- Packet Storm: ProFTPd 1.3.5 File Copy
- Packet Storm: ProFTPd 1.3.5 Remote Command Execution (131555)
- Packet Storm: ProFTPD 1.3.5 Mod_Copy Command Execution
- Packet Storm: ProFTPd 1.3.5 Remote Command Execution (162777)