maybe have your pxe boot service on a vlan or something at least.
at least a decade ago some stuff you wouldn't expect will just connect up to any old server and accept any old image it's offering with no authentication or checks whatsoever. it's annoying when a power outage knocks everything down and some equipment comes up with a different hat on.