Back
CVE-2019-12815
CRITICAL
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.
Published: Jul 19, 2019
Modified: Jun 17, 2026
CWE-755
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (10)
| Vendor | Product | Version |
|---|---|---|
| proftpd | proftpd | * |
| fedoraproject | fedora | 29 |
| fedoraproject | fedora | 30 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| siemens | simatic_cp_1543-1_firmware | * ≥ 2.0 < 2.2 |
GitHub Security Advisory GHSA-f989-xw5v-4w5p
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code...
References (29)
- http://bugs.proftpd.org/show_bug.cgi?id=4372 Exploit, Issue Tracking, Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00004.html Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00022.html Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00009.html Broken Link
- http://www.securityfocus.com/bid/109339 Broken Link, Third Party Advisory, VDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-940889.pdf Third Party Advisory
- https://github.com/proftpd/proftpd/pull/816 Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/08/msg00006.html Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OJDQ3XUYWO42TJBO53NUWDZRA35QMVEI/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XM5FPBAGSIKV6YJZEPM6GPGJO5JFT7XU/
- https://seclists.org/bugtraq/2019/Aug/3 Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201908-16 Third Party Advisory
- https://tbspace.de/cve201912815proftpd.html Patch, Third Party Advisory
- https://www.debian.org/security/2019/dsa-4491 Third Party Advisory
- http://bugs.proftpd.org/show_bug.cgi?id=4372 Exploit, Issue Tracking, Patch, Vendor Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
57.61%
Top 1% most likely to be exploited
Threat Score
56.5 / 100
Data Sources
NVD
EPSS
GitHub