CVE-2019-12815

Modified
Published: 19 Jul 2019, 22:56
Last modified:04 Nov 2025, 16:09

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
78.51% CRITICAL
79% probability -0.31%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

19 Jul 2019, 22:56
Published
Vulnerability first disclosed
04 Nov 2025, 16:09
Last Modified
Vulnerability information updated

Description

An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 78.51% Percentile: 99%

Techniques & Countermeasures

  • CWE-755Improper Handling of Exceptional Conditions

    The product does not handle or incorrectly handles an exceptional condition.

Affected Systems

  • debiandebian_linux

    8.0 | 9.0 | 10.0

  • fedoraprojectfedora

    29 | 30

  • proftpdproftpd

    ≤ 1.3.5b

  • siemenssimatic_cp_1543-1_firmware

    ≥ 2.0, < 2.2

References (15)