I have currently had the same question (7 years later), whether it is possible to update the OpenSSL version in the LTMs without TMOS update, since it is also old and actually deprecated in the current BIG-IP versions.
I open a Service Request #C3461941 with F5 support:
Dear F5 support,
I'd like to ask you this time if there is any possibility to update the openssl version without updating the TMOS itself. Right now the affected boxes are running 13.1.3.4-0.181.5 with openssl-1.0.1l-1.f5.10.0.181.5.
As shown in third party software matrix https://support.f5.com/csp/article/K65097545, this is only included in TMOS version 13.1.3 and I want to know if it's possible to stay with TMOS version 13.1.3 and update openssl separately to latest release 1.1.1 which is only now maintained and supported until 2023-09-11: https://en.wikipedia.org/wiki/OpenSSL
As well the newest release 16.x is running on old outdated openssl-1.0.2u which was supported until 2019-12-31: https://support.f5.com/csp/article/K48851448
I got this feedback:
Unfortunately there is no way for you to upgrade OpenSSL separately on a BIG-IP device.
F5 has numerous instances of OpenSSL on the device which include:
BaseOS, TMOS, iRulesLX (NodeJS), iRulesLX (NodeJS), APM Client, APM Server and OAM (About to EOL).
F5 Network is currently running OpenSSL 1.0.1l across most support platforms for most BIG-IP components.
We already have a development plan in place to next update to OpenSSL 1.1.1 (sub-version TBA) which has no scheduled ETA yet.