The old Sun Microsystems' SunFire SC, (System Controller), was hit with a Microsoft broadcast chatty protocol, that crashed the SCs. This was about 2003 or later, if I recall correctly, (I worked at Sun at the time). While Sun fixed that bug, and probably others related to that problem, Sun started recommending that SCs, (and RSC, ALOMs, SP, etc...), be put on isolated sub-nets that only management servers are allowed to access. This was of course before the degradation of SC / SP / BMCs with web interfaces.
That advice to isolate SP / BMC network interfaces, and certainly not put them on the public network, still applies today.
I mean, who would allow their SP / BMC to be remotely hackable?
Some computer forums have people asking how to access their SP / BMCs from the internet. Really? But, to be fair to some requesting how to make that happen, they want to use a VPN, which probably helps with the security.
Of course, the bug in BMC firmware today is probably not the only one. Just wait, another will be found. Thus, back to isolated network for SP / BMCs...