CVE-2015-3306
ProFTPD ProFTPD — ProFTPD Improper Access Control Vulnerability
Response & Mitigation
Why act now?
Prioritisation rationale
CVE-2015-3306 carries a CVSS v3 score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), meaning a remote, unauthenticated attacker with no user interaction can achieve full confidentiality, integrity, and availability impact with a scope change. In practice, exploitation typically results in webshell deployment or SSH key injection, giving attackers persistent, privileged access to the host. Any organisation running an internet-facing or DMZ-exposed ProFTPD 1.3.5 instance with mod_copy loaded should treat this as a P1 incident regardless of age — legacy FTP infrastructure is a common blind spot in NIS2-scoped environments. The CISA KEV addition in October 2026 confirms continued active exploitation against unpatched systems, making this a credible and immediate threat even for installations that have been running without incident for years.
Runbook · Step 1
Immediate response (0-24 h)
- Patch or stop ProFTPD immediately: The vulnerability affects ProFTPD 1.3.5 with the
mod_copymodule loaded. Upgrade to ProFTPD 1.3.5a / 1.3.6rc1 or later — confirm the exact fixed version in the vendor release notes at https://www.proftpd.org/docs/RELEASE_NOTES. If patching is not immediately possible, stop the service:systemctl stop proftpd. - Disable
mod_copyas an interim control: Comment out or removeLoadModule mod_copy.cfromproftpd.confand restart the daemon. This eliminates the attack vector without a full service outage. - Restrict port 21/tcp at the network perimeter: Apply firewall rules to limit inbound access to port 21 (and passive-mode ports 49152–65535) to authorised source IP ranges only. Disable anonymous FTP access immediately if enabled.
- Hunt for signs of exploitation: Search FTP logs for
SITE CPFRandSITE CPTOcommands (see Detection rules). Inspect the filesystem for unexpected new or modified files — particularly web root directories, SSHauthorized_keysfiles, and cron entries. - Verify ProFTPD process privileges: Confirm the daemon runs under a dedicated, non-privileged service account (
User/Groupdirectives inproftpd.conf). If it runs asroot, arbitrary file writes are system-wide and the blast radius is maximal.
Runbook · Step 2
Mitigation layers
- Network segmentation: Place the FTP server in a dedicated DMZ. Block east-west traffic from the FTP segment to internal systems (databases, AD/LDAP, internal web servers) via firewall policy.
- Permanently remove
mod_copy: If the copy functionality is not operationally required, exclude the module at compile time (--disable-mod-copy) or delete it from the module directory. Enforce this via configuration management (Ansible/Puppet) so it is not re-enabled by package updates. - Enforce chroot jail: Set
DefaultRoot ~inproftpd.confto confine FTP users to their home directories. This preventsSITE CPTOfrom writing to system-critical paths even if the module is present. - Deploy IDS/IPS signature: Create a Suricata rule targeting
SITE CPFRandSITE CPTOon port 21. Example:alert tcp any any -> $FTP_SERVERS 21 (msg:"CVE-2015-3306 ProFTPD mod_copy SITE CPFR"; content:"SITE CPFR"; nocase; sid:9153306; rev:1;). - Least-privilege filesystem ACLs: Restrict the ProFTPD service account to write access only within defined FTP root directories. Explicitly deny access to
/etc,/root,/var/www, and~/.sshvia POSIX ACLs or SELinux/AppArmor policy. - Migrate to SFTP where feasible: Replace FTP with SFTP over OpenSSH and permanently close port 21. This eliminates the attack surface structurally rather than just mitigating this specific CVE.
Runbook · Step 3
Detection rules
- FTP access log search: Grep
/var/log/proftpd/proftpd.logorxferlogforSITE CPFRandSITE CPTO. SPL snippet:index=ftp sourcetype=proftpd ("SITE CPFR" OR "SITE CPTO") | stats count by src_ip, user. - Auditd — unexpected file writes by ProFTPD: Add an auditd rule to catch writes by the ProFTPD binary outside the FTP root:
-a always,exit -F arch=b64 -S open,openat -F exe=/usr/sbin/proftpd -F success=1 -k proftpd_write. Alert on paths matching/etc/,/root/,/var/www/,/.ssh/. - Sigma rule shape (FTP log source):
title: ProFTPD mod_copy Exploitation (CVE-2015-3306) logsource: { product: proftpd, category: ftp } detection: keywords: ['SITE CPFR', 'SITE CPTO'] condition: keywords - Network telemetry (Zeek/Suricata): In Zeek
ftp.log, filter forcommand == "SITE"whereargumentstarts withCPFRorCPTO. Escalate immediately when the target path falls outside the FTP directory tree (e.g./etc/passwd,authorized_keys, web root.php/.jspfiles). - File integrity monitoring: Configure AIDE or Tripwire to alert on changes to
/etc/passwd,/etc/shadow,/root/.ssh/authorized_keys, and web root script files — the typical targets for webshell placement viaSITE CPTO.
Description
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
Affected operating systems
linux
debian / debian_linux7.0
linux
debian / debian_linux8.0
linux
debian / debian_linux9.0
linux
suse / linux_enterprise_server15
linux
opensuse / tumbleweed
other
fedoraproject / fedora20
other
fedoraproject / fedora21
other
fedoraproject / fedora22
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
Metrics
Show all metrics
Public exploit references
Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.
References & sources
- http://www.rapid7.com/db/modules/exploit/unix/ftp/proftpd_modcopy_execx_refsource_MISC
- https://www.exploit-db.com/exploits/36803/exploitx_refsource_EXPLOIT-DB
- http://packetstormsecurity.com/files/131555/ProFTPd-1.3.5-Remote-Command-Execution.htmlx_refsource_MISC
- http://www.debian.org/security/2015/dsa-3263vendor-advisoryx_refsource_DEBIAN
- http://packetstormsecurity.com/files/131567/ProFTPd-CPFR-CPTO-Proof-Of-Concept.htmlx_refsource_MISC
- http://packetstormsecurity.com/files/132218/ProFTPD-1.3.5-Mod_Copy-Command-Execution.htmlx_refsource_MISC
- http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.htmlvendor-advisoryx_refsource_SUSE
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157053.htmlvendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157054.htmlvendor-advisoryx_refsource_FEDORA
- http://www.securityfocus.com/bid/74238vdb-entryx_refsource_BID
- https://www.exploit-db.com/exploits/36742/exploitx_refsource_EXPLOIT-DB
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157581.htmlvendor-advisoryx_refsource_FEDORA
- http://packetstormsecurity.com/files/131505/ProFTPd-1.3.5-File-Copy.htmlx_refsource_MISC
- http://packetstormsecurity.com/files/162777/ProFTPd-1.3.5-Remote-Command-Execution.htmlx_refsource_MISC
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-3306government-resource
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-10-09 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2015-3306","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technica…
- SSVC: {"id":"CVE-2015-3306","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technica…
- Modified Analysis2026-10-09 14:20 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:* *cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:* *cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
- CPE Configuration: OR *cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* *cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* *cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
- CPE Configuration: OR *cpe:2.3:o:opensuse:tumbleweed:-:*:*:*:*:*:*:* *cpe:2.3:o:suse:linux_enterprise_server:15:sp7:*:*:-:-:*:* *cpe:2.3:o:suse:linux_enterprise_server:15:sp7:*:*:-:sap:*:*
- Reference Type: MITRE: http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157053.html Types: Broken Link, Mailing List, Third Party Advisory
- CVE Modified2026-10-09 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2015-3306","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"no"},{"technical…
- SSVC: {"id":"CVE-2015-3306","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technica…
- CVE CISA KEV Update2026-10-08 19:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
- Date Added: 2026-10-08
- Due Date: 2026-10-08
- Required Action: 2026-10-08
- Vulnerability Name: 2026-10-08
- CVE Modified2026-10-08 18:17 UTC· cve@mitre.org
- Reference: http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157053.html
- Reference: http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157054.html
- Reference: http://lists.fedoraproject.org/pipermail/package-announce/2015-May/157581.html
- Reference: http://lists.opensuse.org/opensuse-updates/2015-06/msg00020.html