I suspect many of the affected systems with this port exposed may actually be serving as firewalls themselves, with no other defense between them and the public internet. IPMI might not even be in use ...