In a nutshell, the problem is this. I don't know whether this has changed, but this was true as of 2018 / 2019.
Most of their motherboards have IPMI with a separate a management port. A good number of them share IPMI management with the motherboard's primary ethernet port by default if nothing is plugged in to the management port. The motherboards have no way to configure them to NOT share the primary ethernet port beyond having the full stack of software needed to configure their IPMI.
What this means is that there're no jumpers one can change and no settings accessible in the BIOS that can force IPMI to stay on its own port, so if a BIOS gets reset, the battery dies or even just temporarily fails to provide power (like if it's being shipped by air and gets very cold), or you want to ship servers directly to a datacenter, the machine is 100% ownable on the public interface BY DEFAULT unless the management port is connected (and even then sometimes it decides to share the primary port - probably a function of link negotiation speed with the switch).
Sure, it's not a common occurrence, but it happens.
The solution for all the servers we already had deployed? We got ethernet loopback plugs for every one of them where the IPMI port wasn't already connected to a switch we administered.
A reasonable response: "Sure, that could be a problem sometimes. We can't change motherboards we already sold, but we'll bring this up with our design team so there'll be a jumper you can change so sharing will never happen, even with a reset BIOS."
Their response: "This isn't a security issue."