ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alterations to Viewstate might thus not be noticed.
Weaknesses in this category are typically introduced during the configuration of the software.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.