Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
Overview
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities catalog, which are being actively exploited by a China-linked group known as Flax Typhoon. One of the most critical vulnerabilities is CVE-2015-3306, which has a maximum severity score of 10.0 and involves improper access control in ProFTPD, a popular FTP server software. This exploitation poses a significant risk to federal agencies and other organizations using affected systems, as attackers can potentially gain unauthorized access. CISA has set an October 11 deadline for these agencies to address the vulnerabilities to mitigate the risk of exploitation. Organizations should prioritize applying patches and updates to secure their systems against these threats.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: ProFTPD (specifically affected versions with CVE-2015-3306), federal agency systems using vulnerable software.
- Action Required: Federal agencies must apply patches and updates to ProFTPD to address CVE-2015-3306 and other listed vulnerabilities by October 11, 2023.
- Timeline: Disclosed on October 5, 2023
Original Article Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow
Impact
ProFTPD (specifically affected versions with CVE-2015-3306), federal agency systems using vulnerable software.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Disclosed on October 5, 2023
Remediation
Federal agencies must apply patches and updates to ProFTPD to address CVE-2015-3306 and other listed vulnerabilities by October 11, 2023.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, Critical.