Isn't it a common practice to keep IPMI out of reach of the Internet? At the time I worked with an ISP all management interfaces were connected to a separate network and the only means of accessing it remotely was through a VPN...
Unless vPro is authenticating with 802.11x and you're actually using different passwords for every management interface, a professional cold probably find his way onto that subnet.