For one thing a lot of BMCs are not the easiest to secure and at least KVM devices like a Spider or PiKVM can be patched so that these network accessible devices aren’t so easy to own remotely. A number of BMCs can start advertising and routing to itself across different PHY so even not hooking up the management NIC to a separate LAN won’t be enough then (you’d need to have the right settings and hope you can disable this behavior to avoid such a broadcast across other NICs). I have this issue with my ASRock ASpeed BMC and never got around to fixing it but it bothers me a bit every time I see the IP pop up in my DHCP list and ARP tables.
BMCs can also be patched. HP updates iLO regularly. I even got a major update on my servers adding things like HTML5 consoles (previously it only had .NET and Java which is a pain in this day and age)
And this is for a server I paid $150 for after cashback from HP.
Oh yes, BMCs can certainly be patched but I had the security issue long after the last patch for the motherboard was released so it really comes down to the manufacturer support level as usual. HP likely does better than Supermicro which likely does better than ASRock
Non-server hardware is precisely why I would use this. I'm currently using pikvm on my desktop-class home servers.
Intel AMT is another option assuming you have an Intel CPU SKU and a motherboard that supports it.