CVE-2015-3306: ProFTPD Improper Access Control Vulnerability

Summary

ProFTPD has an improper access control vulnerability allowing remote attackers to read and write to arbitrary files using specific commands. CISA mandates applying vendor-provided mitigations and adhering to BOD 26-04 guidance for federal agencies, with a due date of October 11, 2026. The known ransomware use for this vulnerability is currently unknown.

IFF Assessment

FOE

This vulnerability allows remote attackers to access and modify arbitrary files, posing a significant risk to data integrity and confidentiality.

Severity

8.8 High (AI Estimated)

The vulnerability is rated HIGH (8.8) due to the potential for remote code execution and its impact on confidentiality, integrity, and availability, with an easily reachable attack vector.

CISA KEV: Listed as actively exploited. Federal patch due: October 11, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in ProFTPD allows for arbitrary file read/write, which could be leveraged by attackers for data exfiltration or system compromise. Defenders should prioritize patching or applying mitigations for this known issue, especially given its inclusion in CISA's KEV catalog and potential for ransomware use.

Read Full Story →