Run an FTP server with ProFTPD? Patch it now
Businesses that run their own ProFTPD file-transfer server, typically version 1.3.5, set up by an IT provider or an in-house system administrator rather than something that comes pre-installed. If your business exchanges files through a cloud service like Dropbox or SharePoint, or a dedicated SFTP provider, this isn't your equipment.
ProFTPD is free software some businesses run themselves to accept file uploads or send files back and forth with suppliers and customers over FTP (File Transfer Protocol), instead of paying for a managed file-transfer service. A flaw in one of its add-ons lets anyone connect without logging in at all and tell the server to copy any file to anywhere else on the system, which an attacker can use to read sensitive files or plant one that hands them full control. ProFTPD fixed this back in 2015, but the US government has only now confirmed criminals are actively exploiting it, a sign that old, forgotten installs are still being found on the internet.
Do this
Ask whoever manages your file-transfer server: "Are we running ProFTPD, and has it been updated to version 1.3.5a or later?"
Sources: CISA KEV: ProFTPD flaw ↗ · Debian Security Tracker: CVE-2015-3306 ↗CVE-2015-3306 · CWE-284