In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.html
https://github.com/openbmc/openbmc
https://github.com/google/security-research/security/advisories/GHSA-gg9x-v835-m48q