ReptileMan parent
Supermicro IPMI comes to mind. If it was compromised we would have known by now.
Not only is Supermicro headquartered in USA, but it's operations are in Taiwan, which they would very much like you to acknowledge is not the same as mainland China.
Memory sure is short around here.
There's a lot of vulnerabilities, of course. Supermicro isn't great at releasing updates for old boards either.
https://www.cve.org/CVERecord/SearchResults?query=supermicro