>>zdw+(OP)
If you've never used the BMC on a server... it is all 100% garbage. Software mostly written by embedded folks who haven't got a clue. It is absolutely garbage software on the whole (and no matter what vendor you get the board from). Go ahead and hit up the web interface then do a bit of "View Source". If you are imagining the rest of that stack is any better than my friend have I got a Beautiful Bridge in Brooklyn to sell you!
If it were me I'd assume the majority of BMC firmware out there from all vendors:
1. Is full of many many exploitable vulnerabilities
2. To the extent they patch holes it will be whack-a-mole because the economics do not permit large investments in software quality.
3. Many server owners will never install a patch anyway.