Back

CVE-2019-12815

CRITICAL

An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.

Published: Jul 19, 2019 Modified: Jun 17, 2026
CWE-755

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (10)

Vendor Product Version
proftpd proftpd *
fedoraproject fedora 29
fedoraproject fedora 30
debian debian_linux 8.0
debian debian_linux 9.0
debian debian_linux 10.0
debian debian_linux 8.0
debian debian_linux 9.0
debian debian_linux 10.0
siemens simatic_cp_1543-1_firmware * ≥ 2.0 < 2.2

GitHub Security Advisory GHSA-f989-xw5v-4w5p

An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 57.61%

Top 1% most likely to be exploited

Threat Score 56.5 / 100

Data Sources

NVD EPSS GitHub