Agreed. IPMI/iDrac/iLo present with vulnerabilities like any software.
For those concerned about firmware updates breaking servers, or
otherwise causing undesirable behavior, I suggest you ensure you have a
test machine in the lab https://100001.onl/...