IPMI cards are always-on, and run outside the rest of the server. They receive power even if the server is shut down. These are used for out-of-band management, power on/off, etc. Imagine if someone were to have control of the firmware running on your IPMI cards... they would have physical access to your server (essentially) from a remote location. You often don't control what's running on the IPMI cards or if they call home, etc. What if HP or Dell had sleeper software in your IPMI cards, and when it wakes up, opens a direct connection to your server?
Take for instance Intel's addons to IPMI "Automatic Management Technology".
Let's say you have a server, reachable on a certain network address on a LAN.
I can turn on AMT, I can set up server management answerable at the SAME address. network traffic to and from the machine and network is undisturbed.
I can install bios updates, configure aspects of the machine, all kinds of things, just with AMT. I have read in some cases you can configure the machine this way even if its powered off.
[1] https://en.wikipedia.org/wiki/Intelligent_Platform_Managemen...