Status: KEV
| Advisory ID: CVE-2015-3306
Key Details
| CVE | CVE-2015-3306 |
| Vulnerability Name | ProFTPD Improper Access Control Vulnerability |
| Affected products | ProFTPD ProFTPD |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-284 (Improper Access Control) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-10-08. |
| Federal remediation deadline | 2026-10-11 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
What to Do
Monitor ProFTPD's web page for any future patch releases.
References
KEV Required Action