Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Improper Access Control in ProFTPD (CVE‑2015‑3306) Enables Remote File Read/Write

ProFTPD versions before 1.3.5a allow unauthenticated attackers to read or overwrite arbitrary files via FTP commands. The flaw underscores the need for auditable access‑control evidence and continuous monitoring to satisfy trust‑focused compliance reviews.

LiveThreat™ Intelligence · 📅 October 09, 2026· 📰 nvd.nist.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
5 recommended
📰
Source
nvd.nist.gov

Improper Access Control in ProFTPD (CVE‑2015‑3306) Allows Remote File Read/Write

What It Is — ProFTPD versions prior to 1.3.5a contain an improper access‑control flaw in the site cpfr and site cpto commands. An unauthenticated remote attacker can leverage these commands to read or overwrite arbitrary files on the FTP server.

Exploitability — The vulnerability is publicly disclosed; proof‑of‑concept code exists and the CVSS v3.1 base score is 7.5 (High). No known active exploit campaigns, but the attack vector is trivial for anyone with network access to the service.

Affected Products — ProFTPD FTP server (all releases before the security‑patched 1.3.5a).

Why It Matters for Trust & Control Assurance

  • Continuous verification that access‑control configurations match policy is essential; a single mis‑configured command can break the entire trust posture.
  • Evidence‑ready audit logs and configuration baselines become critical proof points when auditors ask how unauthorized file access is prevented.
  • Enterprise buyers now demand demonstrable, repeatable controls around remote service hardening and least‑privilege file permissions.

Recommended Actions

  • Apply the vendor’s patch (upgrade to ProFTPD 1.3.5a or later).
  • Disable or restrict the site cpfr/cpto commands if they are not required.
  • Harden file‑system permissions to enforce least‑privilege access for the FTP service account.
  • Enable detailed FTP command logging and integrate logs into a centralized SIEM for continuous monitoring.
  • Map the access‑control requirement to your control framework and capture remediation evidence in a Trust Center repository.

Source: CISA KEV – CVE‑2015‑3306

📰 Original Source
https://nvd.nist.gov/vuln/detail/CVE-2015-3306 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →