We are using the X10SRI-F with 2.18 IPMI Firmware and the ran a Nessus security scan against the server and found the following issues.
"Plugin: IPMI v2.0 Password Hash Disclosure (80101)"
"Plugin: VNC Security Type Enforcement Failure Remote Authentication Bypass (21564)"
It has been fixed in IPMI 3.44. However, we are aware of another issue with the drop bear SSH module, and that will be fixed in a newer firmware release.