← Blog · · df00tech

CISA KEV Adds Decade-Old ProFTPD mod_copy Vulnerability (CVE-2015-3306) Amid Active Exploitation

breaking kev ProFTPD CVE-2015-3306

CISA has added CVE-2015-3306, an improper access control vulnerability in ProFTPD, to its Known Exploited Vulnerabilities (KEV) catalog, per ProFTPD's advisory. The flaw lies in the mod_copy module's SITE CPFR and SITE CPTO commands, which can be abused by unauthenticated remote attackers to copy files to and from arbitrary locations on the filesystem.

Why It Matters

Although this vulnerability was originally disclosed over a decade ago, its inclusion in CISA KEV confirms it is being actively exploited in the wild today. Any organization still running an unpatched, internet-facing ProFTPD server with mod_copy enabled remains exposed. The vulnerability's nature — arbitrary file read/write without authentication — makes it well suited for dropping web shells, exfiltrating sensitive files (including credentials or configs), or achieving full remote code execution when combined with a writable web root. CISA has not indicated known ransomware campaign use at this time, but KEV listing alone signals confirmed real-world exploitation and should be treated as urgent.

What Defenders Should Do Now

  • Inventory all ProFTPD instances, especially those exposed to the internet, and check version/patch status.
  • Apply vendor patches or disable/remove the mod_copy module if patching isn't immediately possible.
  • Hunt for anomalous use of SITE CPFR / SITE CPTO commands in FTP server logs, particularly paths referencing files outside expected upload directories (e.g., web-accessible paths, SSH keys, or config files).
  • Watch for unexpected new files appearing in web roots or other sensitive directories shortly after FTP sessions.
  • Review network egress and host logs for follow-on activity consistent with web shell deployment if a writable path was exposed.

This is a same-day addition to CISA KEV and details on exploitation methodology or threat actors are not yet public. This post will be revisited as more intelligence becomes available. See the original source at proftpd.org.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.