Improper Access Control in ProFTPD (CVE‑2015‑3306) Exploited by Flax Typhoon Threat Actor
What It Is — A critical improper‑access‑control flaw in the open‑source ProFTPD FTP server allows an unauthenticated attacker to bypass authentication and gain full file‑system access.
Exploitability — Actively exploited in the wild by the China‑linked “Flax Typhoon” group; CVSS 3.1 base score 10.0 (critical). No public proof‑of‑concept is required – the vulnerability is weaponised in multiple campaigns.
Affected Products — ProFTPD (all versions prior to the security‑only release that addresses CVE‑2015‑3306).
Why It Matters for Trust & Control Assurance
- Access‑control hygiene is a core control objective; a single bypass defeats the “least‑privilege” guarantee that auditors expect.
- Continuous evidence of patch status and configuration drift detection is essential to prove due‑diligence during a security review.
- Demonstrable logging of FTP authentication attempts provides a defensible audit trail that regulators and enterprise buyers increasingly demand.
Recommended Actions
- Patch immediately to the version that resolves CVE‑2015‑3306 (or apply the vendor‑provided back‑port).
- Validate configuration – ensure
AllowOverwriteandAuthUserFiledirectives follow the principle of least privilege. - Enable and centralise FTP logs – forward to a SIEM or log‑aggregation service for real‑time monitoring.
- Run a vulnerability scan focused on known KEV entries to confirm no other catalogued flaws remain unaddressed.
Source: The Hacker News