Information Disclosure Vulnerability in Nuance PowerScribe by Nuance
CVE-2025-30398

8.1HIGH

What is CVE-2025-30398?

The vulnerability in Nuance PowerScribe allows attackers to bypass authorization mechanisms, potentially exposing sensitive information over the network. This flaw could lead to unauthorized data access, affecting the confidentiality of sensitive patient and medical reporting data. Organizations using Nuance PowerScribe should take immediate action to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Nuance PowerScribe 360 version 4.0.1 Unknown 4.0.1 < 7.0.111.66

Nuance PowerScribe 360 version 4.0.2 Unknown 4.0.2 < 7.0.154.16

Nuance PowerScribe 360 version 4.0.3 Unknown 4.0.3 < 7.0.197.8

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-30398 : Information Disclosure Vulnerability in Nuance PowerScribe by Nuance