| CVE | CVE-2015-3306 |
| Vulnerability Name | ProFTPD Improper Access Control Vulnerability |
| CVSS Score / Version | 10.0 (Critical) / CVSS v3.1 |
| Updated | 2026-10-09 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | ProFTPD ProFTPD and suse linux_enterprise_server |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-284 (Improper Access Control) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-10-08. |
| Exploitation prediction (EPSS) | 98.03% probability of exploitation in the next 30 days (100% percentile) -- FIRST.org's EPSS model. |
| Federal remediation deadline | 2026-10-11 (CISA KEV, Binding Operational Directive). |
ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
Monitor ProFTPD's and suse's web pages for any future patch releases.