Quick answer
Direct answer
What is ProFTPD?
ProFTPD is an FTP server used to provide file transfer services. Administrators operate this kind of software when users, applications, or business partners need to exchange files with a central system. If you manage one of these services, your security responsibility extends beyond keeping transfers available. You also need to ensure that each connection can access only the files and operations it is authorized to use.
A file transfer server sits at an important trust boundary. It accepts network activity while interacting with storage that may also support other business functions. Your deployment might serve a narrow, dedicated directory, or it might share a host with other services. Those choices matter when you assess exposure because the surrounding environment helps determine the consequences of unauthorized file access.
The component relevant here is mod_copy, a ProFTPD module associated with file copying operations. CVE-2015-3306 concerns that module in ProFTPD 1.3.5. For your assessment, the product name alone is not enough. You need to establish the deployed software version, whether the relevant component is present and active, and who can reach the service.
CVE-2015-3306 at a glance
| Field | Detail |
|---|---|
| CVE ID | CVE-2015-3306 |
| Product | ProFTPD ProFTPD |
| Severity | CRITICAL |
| CVSS base score | 10 |
| CVSS vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS probability | 96.75 percent (percentile 100) |
| CISA KEV | Yes, added 2026-10-08 |
| Weakness | CWE-284, CWE-284 |
| Affected versions | Proftpd 1.3.5 |
| Published | May 18, 2015 |
CISA required action
What the flaw is
The verified description identifies remote arbitrary file reading and writing through the site cpfr and site cpto commands. These names identify the affected command interface, not a recommended test procedure. At a conceptual level, the security failure is that a remote party can cause file operations that should be controlled by an authorization boundary.
The supplied classification is CWE-284, improper access control. The central question is not simply whether copying files is a legitimate feature. It is whether the service reliably prevents an unauthorized party from using that feature to access protected data or alter files. A useful administrative capability becomes dangerous when its access controls do not enforce the intended separation.
The supplied assessment is critical, with CVSS 10. Its vector describes network access, low attack complexity, no required privileges, and no required user interaction. It also describes changed scope and high confidentiality, integrity, and availability impact. You should therefore not treat an ordinary login requirement as sufficient evidence that the vulnerable functionality is protected.
Arbitrary file access describes the vulnerability, but it does not establish the exact outcome on every server. Host permissions, accessible storage, and relationships with other services still need investigation. Do not automatically equate every installation with full system takeover. Equally, do not dismiss the flaw because you have not demonstrated a more extensive compromise. Unauthorized reading or writing already creates a serious security problem.
How an attack could happen
Consider a hypothetical organization running an affected ProFTPD service that is reachable from an untrusted network. The following scenario explains the trust boundary at risk without describing an exploitation procedure. Its consequences depend on the files and surrounding services available in that particular deployment.
- 1An attacker can reach the affected service. For the defender, this establishes an exposure question: which outside parties can connect, and does the deployed service include the vulnerable component?
- 2The attacker abuses the file copying functionality to cross an access boundary. The important failure is unauthorized file access, rather than a user being persuaded to open something or approve an action.
- 3Sensitive information could be exposed, or files could be altered where the deployment permits the relevant access. Additional consequences would depend on how the organization uses those files.
- 4The organization must both remove the vulnerable exposure and assess whether unauthorized activity occurred. Restoring a secure configuration does not, by itself, establish that earlier access left no consequences.
Impact
Confidentiality is at risk because the flaw allows arbitrary file reading. In your environment, assess whether reachable files could contain business data, operational settings, or secrets. These are categories to investigate, not confirmed contents of any affected installation. If evidence indicates that secrets were exposed, addressing the software flaw alone would not resolve their continued misuse.
Integrity is at risk because the flaw also allows arbitrary file writing. Unauthorized changes could undermine the trustworthiness of stored information or files used by other processes. Availability consequences could follow if important files were damaged or changed. The supplied severity assessment recognizes high impact across all three areas, but your incident findings should distinguish possible effects from observed effects.
CVE-2015-3306 is in the CISA Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. That establishes real exploitation, not compromise of your particular server. The supplied ransomware association is unknown. Do not translate that uncertainty into either a claim of ransomware involvement or reassurance that ransomware is irrelevant.
Who is affected
The explicitly identified affected release is ProFTPD 1.3.5, with the vulnerability located in mod_copy. Use that as the starting point for inventory and investigation. The supplied facts do not establish a complete affected version range or identify a fixed release. For other versions, package builds, and remediation status, check the applicable vendor advisory rather than extrapolating.
Prioritize deployments reachable from untrusted networks, but do not stop at your public perimeter. Review internal servers, partner access paths, and deployments whose ownership is unclear. These are suggested discovery areas, not claims that every such service is vulnerable. Record evidence for the software identity, component configuration, network access, and system owner so that uncertainty remains visible.
How to detect it
- Start with an inventory search for ProFTPD and confirm results using deployment records or authorized host inspection. Treat a network banner as a discovery lead rather than conclusive proof of the installed package or its remediation status.
- Review the effective configuration and component inventory for mod_copy. Where configuration files and observed service behavior disagree, investigate which configuration the running service actually uses. Record the evidence and its collection time.
- Map access from the internet, partner networks, and internal segments. Describe the permitted sources and the control enforcing each restriction. A statement that a server is internal is less useful than evidence showing who can connect.
- Where your logging captures FTP commands, search in words for activity involving site cpfr and site cpto. Examine unexpected sources, unusual timing, and activity inconsistent with normal transfers. A command name alone does not prove exploitation.
- Correlate suspicious service activity with available file access records, file integrity alerts, and unexpected changes in relevant storage. Look for connections between the network event and the filesystem change rather than treating unrelated anomalies as confirmation.
- Document logging limitations before drawing conclusions. Missing command records or incomplete filesystem visibility can prevent a reliable determination of past abuse. An absence of alerts is not equivalent to evidence that no unauthorized access occurred.
How to fix and reduce risk
Do this now
- Assign an accountable service owner and establish whether the deployment matches the known affected product and component. Escalate confirmed exposure promptly because the vulnerability is critical and has known exploitation.
- Restrict network access to required, trusted sources while remediation is arranged. If you cannot justify keeping the service reachable, consider isolating it or pausing it through your incident and change management processes.
- Consult the applicable ProFTPD or distribution vendor advisory and apply its supported remediation. The supplied facts do not identify a fixed version, so do not select an upgrade target from this article alone.
- If suspicious activity is present, involve incident response and preserve relevant logs and system evidence before disruptive changes when feasible. Coordinate preservation with urgent containment rather than allowing either activity to proceed without the other.
If you cannot patch yet
- If file copying functionality is not required, evaluate disabling mod_copy using vendor supported guidance. Confirm that the running service no longer exposes the functionality and test essential business workflows. Treat this as a control requiring verification, not an assumed fix.
- Reduce unnecessary access to storage and separate unrelated sensitive data from the service where operationally feasible. These measures can limit potential consequences, but they do not establish that the underlying vulnerability has been corrected.
- Give every temporary restriction an owner, an expiry review, and a remediation dependency. An access rule that blocks one route may leave another route open, so validate the restriction from the relevant network perspectives.
Longer term hardening
- Maintain a supported deployment and retain evidence of the vendor guidance used to choose the remediation. After changes, verify the running software and configuration rather than relying only on a successful maintenance ticket.
- Follow the applicable CISA remediation and forensics triage guidance referenced by the catalog entry, including guidance relevant to cloud services. The supplied required action also calls for discontinuing use if mitigations are unavailable.
- Review whether the business still needs the service and each enabled capability. Link future deployment changes to asset inventory, exposure monitoring, and ownership records so that replacement systems do not silently recreate the same risk.
The CTEM view
| CTEM stage | What to do for this CVE |
|---|---|
| Scope | Define the business processes that depend on ProFTPD, the storage they use, and the network paths that support them. Include responsibility for the host, application, and data. Your scope should explain what must remain operational and what requires protection, giving remediation decisions a business context instead of treating the server as an isolated scan result. |
| Discover | Combine software inventory, configuration review, and network exposure evidence. Seek a defensible answer to whether ProFTPD 1.3.5 and the relevant module are deployed, not just whether an FTP endpoint exists. Keep uncertain findings open with a named investigation owner. Lack of inventory evidence should not silently become a conclusion that the asset is safe. |
| Prioritize | Use known exploitation, CVSS 10, and EPSS 96.75 percent alongside your environment specific evidence. The EPSS value is a prioritization signal, not a measurement that your host has been compromised. Give particular attention to reachable affected services, sensitive storage, and weak visibility. Separate urgency to remediate from confidence about whether an incident has occurred. |
| Validate | Validate findings through approved, non destructive checks of software identity, module configuration, and access restrictions. You do not need to read sensitive files or change production data to demonstrate responsible exposure management. Define closure evidence in advance, then verify that the running deployment matches the chosen remediation and that required business functions still work. |
| Mobilize | Turn the finding into coordinated work for service owners, infrastructure teams, network administrators, and incident responders where needed. Track interim containment separately from permanent remediation and investigation. Close each workstream on its own evidence. This prevents a completed upgrade from obscuring unresolved questions about earlier file access or an undocumented temporary network exception. |
Key takeaways
- CVE-2015-3306 affects mod_copy in ProFTPD 1.3.5 and allows remote arbitrary file reading and writing through the affected command interface.
- Known exploitation makes this an urgent exposure management issue. It does not establish that every affected server has already been compromised.
- Confirm the running software, relevant component, and actual network access before making a confident exposure or remediation claim.
- Use vendor guidance to identify the supported fix. The provided facts do not name a fixed version or establish the status of other releases.
- Treat containment, permanent remediation, and investigation as related but distinct tasks, each requiring an owner and evidence of completion.
Frequently asked questions
Related pages
CTEM Prioritization Signals
CTEM Prioritization: KEV, EPSS, CVSS, Business Impact
How to combine CVSS, CISA KEV, EPSS, reachability and business impact into a CTEM prioritization model your engineering teams will actually accept.
Zero Day CTEM Workflow
Zero Day Response Workflow with CTEM
A practical zero day response workflow built on CTEM: confirm the advisory, query the inventory, triage by exposure, mitigate, validate and verify closure.
Compensating Controls in CTEM
Compensating Controls in CTEM: When You Cannot Patch
How to use compensating controls in CTEM: five options when patching is impossible, validating that a control blocks the technique, and writing a defensible exception.
Vulnerability Management Learning Path
Free Vulnerability Management Training Path | LearnCTEM
Follow a free vulnerability management learning path covering CVSS, KEV, EPSS, prioritization, remediation, practical labs and CTEM certification.
Earn your free CTEM certification.
Learn to scope, prioritize, validate and mobilize fixes for CVEs like this one.
Beginner / Practitioner / Program Leader
Explore certificationsAuthor
LearnCTEM Editorial Team
Practitioners and educators writing plain-English guides on Continuous Threat Exposure Management.
Reviewed by
Senior CTEM Practitioner Panel
Reviewed for accuracy against public CTEM guidance and real-world program experience.

