Improper Access Control in ProFTPD (CVE‑2015‑3306) Allows Remote File Read/Write
What It Is — ProFTPD versions prior to 1.3.5a contain an improper access‑control flaw in the site cpfr and site cpto commands. An unauthenticated remote attacker can leverage these commands to read or overwrite arbitrary files on the FTP server.
Exploitability — The vulnerability is publicly disclosed; proof‑of‑concept code exists and the CVSS v3.1 base score is 7.5 (High). No known active exploit campaigns, but the attack vector is trivial for anyone with network access to the service.
Affected Products — ProFTPD FTP server (all releases before the security‑patched 1.3.5a).
Why It Matters for Trust & Control Assurance
- Continuous verification that access‑control configurations match policy is essential; a single mis‑configured command can break the entire trust posture.
- Evidence‑ready audit logs and configuration baselines become critical proof points when auditors ask how unauthorized file access is prevented.
- Enterprise buyers now demand demonstrable, repeatable controls around remote service hardening and least‑privilege file permissions.
Recommended Actions
- Apply the vendor’s patch (upgrade to ProFTPD 1.3.5a or later).
- Disable or restrict the
site cpfr/cptocommands if they are not required. - Harden file‑system permissions to enforce least‑privilege access for the FTP service account.
- Enable detailed FTP command logging and integrate logs into a centralized SIEM for continuous monitoring.
- Map the access‑control requirement to your control framework and capture remediation evidence in a Trust Center repository.
Source: CISA KEV – CVE‑2015‑3306