Another perfect reason not to expose management interfaces to the internet, but people keep doing it!
It wasn't that long ago that iLO-1 and iLO-2 interfaces were being popped and replaced with malicious copies of the firmware.
Nothing, other than what you want the public to touch, should ever be on the internet with a public IP or via a port forward, with the exception of your VPN server itself.