@Jeff Thorne Thank you for reaching out to us, As I understand you have queries on the OpenSSL vulnerabilities showing in Defender Dashboard.
Researched on your issue and found few changes happened from 3.0.9 to 3.0.10 and notes for the same can be found here - https://www.openssl.org/news/openssl-3.0-notes.html
Could you help me which defender dashboard has discovered these vulnerabilities on your devices, if any screenshot which you can share (if it contains sensitive information, feel free to send me an email to 'AzCommunity@microsoft.com' with Sub - Attn: Givary so that I can review it further).
However similar issue was discussed in the past - https://msrc.microsoft.com/blog/2022/11/microsoft-guidance-related-to-openssl-risk-cve-2022-3786-and-cve-2202-3602/ where the mitigation was to update the OS/respective software having this DLL.
Also would recommend to check if you have any security updates pending for these devices, if yes install them and check if defender still reports.
Reference:
Whether these alerts are false positive or not, I can tell after receiving the screenshot from the defender dashboard, so that I can discuss it with my team internally on the same.
Let me know if you have any further questions, feel free to post back.
Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.