CVE-2015-3306

ProFTPD ProFTPD — ProFTPD Improper Access Control Vulnerability

Response & Mitigation

Why act now?

Prioritisation rationale

CVE-2015-3306 carries a CVSS v3 score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), meaning a remote, unauthenticated attacker with no user interaction can achieve full confidentiality, integrity, and availability impact with a scope change. In practice, exploitation typically results in webshell deployment or SSH key injection, giving attackers persistent, privileged access to the host. Any organisation running an internet-facing or DMZ-exposed ProFTPD 1.3.5 instance with mod_copy loaded should treat this as a P1 incident regardless of age — legacy FTP infrastructure is a common blind spot in NIS2-scoped environments. The CISA KEV addition in October 2026 confirms continued active exploitation against unpatched systems, making this a credible and immediate threat even for installations that have been running without incident for years.

Runbook · Step 1

Immediate response (0-24 h)

  • Patch or stop ProFTPD immediately: The vulnerability affects ProFTPD 1.3.5 with the mod_copy module loaded. Upgrade to ProFTPD 1.3.5a / 1.3.6rc1 or later — confirm the exact fixed version in the vendor release notes at https://www.proftpd.org/docs/RELEASE_NOTES. If patching is not immediately possible, stop the service: systemctl stop proftpd.
  • Disable mod_copy as an interim control: Comment out or remove LoadModule mod_copy.c from proftpd.conf and restart the daemon. This eliminates the attack vector without a full service outage.
  • Restrict port 21/tcp at the network perimeter: Apply firewall rules to limit inbound access to port 21 (and passive-mode ports 49152–65535) to authorised source IP ranges only. Disable anonymous FTP access immediately if enabled.
  • Hunt for signs of exploitation: Search FTP logs for SITE CPFR and SITE CPTO commands (see Detection rules). Inspect the filesystem for unexpected new or modified files — particularly web root directories, SSH authorized_keys files, and cron entries.
  • Verify ProFTPD process privileges: Confirm the daemon runs under a dedicated, non-privileged service account (User/Group directives in proftpd.conf). If it runs as root, arbitrary file writes are system-wide and the blast radius is maximal.

Runbook · Step 2

Mitigation layers

  • Network segmentation: Place the FTP server in a dedicated DMZ. Block east-west traffic from the FTP segment to internal systems (databases, AD/LDAP, internal web servers) via firewall policy.
  • Permanently remove mod_copy: If the copy functionality is not operationally required, exclude the module at compile time (--disable-mod-copy) or delete it from the module directory. Enforce this via configuration management (Ansible/Puppet) so it is not re-enabled by package updates.
  • Enforce chroot jail: Set DefaultRoot ~ in proftpd.conf to confine FTP users to their home directories. This prevents SITE CPTO from writing to system-critical paths even if the module is present.
  • Deploy IDS/IPS signature: Create a Suricata rule targeting SITE CPFR and SITE CPTO on port 21. Example: alert tcp any any -> $FTP_SERVERS 21 (msg:"CVE-2015-3306 ProFTPD mod_copy SITE CPFR"; content:"SITE CPFR"; nocase; sid:9153306; rev:1;).
  • Least-privilege filesystem ACLs: Restrict the ProFTPD service account to write access only within defined FTP root directories. Explicitly deny access to /etc, /root, /var/www, and ~/.ssh via POSIX ACLs or SELinux/AppArmor policy.
  • Migrate to SFTP where feasible: Replace FTP with SFTP over OpenSSH and permanently close port 21. This eliminates the attack surface structurally rather than just mitigating this specific CVE.

Runbook · Step 3

Detection rules

  • FTP access log search: Grep /var/log/proftpd/proftpd.log or xferlog for SITE CPFR and SITE CPTO. SPL snippet: index=ftp sourcetype=proftpd ("SITE CPFR" OR "SITE CPTO") | stats count by src_ip, user.
  • Auditd — unexpected file writes by ProFTPD: Add an auditd rule to catch writes by the ProFTPD binary outside the FTP root: -a always,exit -F arch=b64 -S open,openat -F exe=/usr/sbin/proftpd -F success=1 -k proftpd_write. Alert on paths matching /etc/, /root/, /var/www/, /.ssh/.
  • Sigma rule shape (FTP log source):
    title: ProFTPD mod_copy Exploitation (CVE-2015-3306)
    logsource: { product: proftpd, category: ftp }
    detection:
      keywords: ['SITE CPFR', 'SITE CPTO']
    condition: keywords
    
  • Network telemetry (Zeek/Suricata): In Zeek ftp.log, filter for command == "SITE" where argument starts with CPFR or CPTO. Escalate immediately when the target path falls outside the FTP directory tree (e.g. /etc/passwd, authorized_keys, web root .php/.jsp files).
  • File integrity monitoring: Configure AIDE or Tripwire to alert on changes to /etc/passwd, /etc/shadow, /root/.ssh/authorized_keys, and web root script files — the typical targets for webshell placement via SITE CPTO.

Description

The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

Affected operating systems

  • linux

    debian / debian_linux7.0

  • linux

    debian / debian_linux8.0

  • linux

    debian / debian_linux9.0

  • linux

    suse / linux_enterprise_server15

  • linux

    opensuse / tumbleweed

  • other

    fedoraproject / fedora20

  • other

    fedoraproject / fedora21

  • other

    fedoraproject / fedora22

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

proftpdproftpd

Metrics

10.0
Source: cna-v3
99.9 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Actively exploited
Show all metrics
Severity
critical
actively exploited (KEV)
98.0 %
High — model estimates ≥ 50% chance of real-world exploitation within 30 days.
Published
2015-05-18 15:59 UTC

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-09 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2015-3306","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technica…
    • SSVC: {"id":"CVE-2015-3306","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technica…
  2. Modified Analysis2026-10-09 14:20 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:* *cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:* *cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
    • CPE Configuration: OR *cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* *cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* *cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
    • CPE Configuration: OR *cpe:2.3:o:opensuse:tumbleweed:-:*:*:*:*:*:*:* *cpe:2.3:o:suse:linux_enterprise_server:15:sp7:*:*:-:-:*:* *cpe:2.3:o:suse:linux_enterprise_server:15:sp7:*:*:-:sap:*:*
    • Reference Type: MITRE: http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157053.html Types: Broken Link, Mailing List, Third Party Advisory
  3. CVE Modified2026-10-09 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2015-3306","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technical…
    • SSVC: {"id":"CVE-2015-3306","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technica…
  4. CVE CISA KEV Update2026-10-08 19:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
    • Date Added: 2026-10-08
    • Due Date: 2026-10-08
    • Required Action: 2026-10-08
    • Vulnerability Name: 2026-10-08
  5. CVE Modified2026-10-08 18:17 UTC· cve@mitre.org
    • Reference: http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157053.html
    • Reference: http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157054.html
    • Reference: http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157581.html
    • Reference: http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html

Linked advisories