Sorry to say, but so far you fail to clearly understand that a tool like
nessus just looks at the version tag it can get. It cannot see that the
fix backported by Red Hat is incorporated into an openssl release which
does not have this fix in upstream at the same version.

That's why Stephen earlier said "Don't trust nessus scans". But you can
trust what Red Hat publishes in their errata reports and CVE database.