Full Report
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow
Analysis Summary
# Vulnerability: Multiple Flaws Exploited by Flax Typhoon (China-linked Actor)
## CVE Details
- **CVE ID:** CVE-2015-3306, CVE-2021-3199, CVE-2023-22894, CVE-2016-3081, CVE-2015-5477
- **CVSS Score:** Range 7.2 to 10.0 (High to Critical)
- **CWE:** CWE-284 (Improper Access Control), CWE-22 (Path Traversal), CWE-312 (Cleartext Storage of Sensitive Information), CWE-77 (Command Injection), CWE-617 (Reachable Assertion)
## Affected Systems
- **Products:**
- ProFTPD (File Transfer Protocol daemon)
- ONLYOFFICE Docs
- Strapi (Headless CMS)
- Apache Struts
- ISC BIND (DNS software)
- **Versions:**
- ProFTPD: Version 1.3.5 (mod_copy module)
- ONLYOFFICE Docs: Versions prior to 6.3
- Strapi: Versions prior to 4.5.5
- Apache Struts: Versions 2.3.20 through 2.3.28 (with specific exceptions)
- ISC BIND: 9.1.0 to 9.8.x, 9.9.0 to 9.9.7-P1, 9.10.0 to 9.10.2-P2
- **Configurations:**
- **CVE-2015-3306:** Requires `mod_copy` enabled.
- **CVE-2021-3199:** Occurs when JSON Web Token (JWT) is used.
- **CVE-2016-3081:** Requires Dynamic Method Invocation (DMI) enabled.
## Vulnerability Description
This suite of vulnerabilities represents a diverse attack surface used for initial access:
- **CVE-2015-3306:** Abuse of `site cpfr` and `site cpto` commands to read/write arbitrary files.
- **CVE-2021-3199:** Path traversal via "/.." in image upload parameters leading to Remote Code Execution (RCE).
- **CVE-2023-22894:** Sensitive data exposure via query filters in the admin panel.
- **CVE-2016-3081:** RCE via `method:prefix` in the Struts framework.
- **CVE-2015-5477:** Denial-of-Service (DoS) triggered by specifically crafted TKEY queries.
## Exploitation
- **Status:** **Exploited in the wild** by Flax Typhoon (Integrity Technology Group). Included in CISA KEV.
- **Complexity:** Low to Medium
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Data exfiltration and sensitive detail discovery)
- **Integrity:** High (Arbitrary file writes and RCE)
- **Availability:** High (System takeover and DoS via BIND)
## Remediation
### Patches
- **ProFTPD:** Upgrade to version 1.3.5a or later.
- **ONLYOFFICE Docs:** Upgrade to version 6.3 or later.
- **Strapi:** Upgrade to version 4.5.5 or later.
- **Apache Struts:** Upgrade to version 2.3.28.1 or 2.5.
- **ISC BIND:** Apply patches provided in ISC advisory (e.g., 9.9.7-P2, 9.10.2-P3).
### Workarounds
- **ProFTPD:** Disable `mod_copy` if not required.
- **Apache Struts:** Disable Dynamic Method Invocation (`struts.enable.DynamicMethodInvocation = false`).
- **General:** Implement strict IP whitelisting for admin panels and FTP services.
## Detection
- **Indicators of Compromise:** Look for unauthorized `site cpfr/cpto` commands in FTP logs; monitor for directory traversal sequences (`/..`) in web server upload logs.
- **Detection methods:** CISA KEV monitoring, vulnerability scanning for legacy software versions, and monitoring for unusual TKEY queries in DNS traffic.
## References
- **CISA KEV Catalog:** hxxps://www.cisa[.]gov/known-exploited-vulnerabilities-catalog
- **ISC Advisory (CVE-2015-5477):** hxxps://kb.isc[.]org/docs/aa-01272
- **Vendor Advisory:** hxxps://thehackernews[.]com/2026/10/flax-typhoon-exploits-five-flaws-as.html