In its September 2 advance notice, Arista did not list CVEs, severity ratings or affected versions. This article records what was known on September 6.

On September 2, Arista said it planned to publish a batch of security advisories for EOS and VeloCloud on September 9. The advisories were expected to describe vulnerabilities and recommended fixes. This report describes the advance notice available at the time, not the later advisories.
As of September 6, the company had not disclosed CVE identifiers, severity levels or affected software versions in that notice. It did not report active exploitation of the vulnerabilities it planned to describe.
What administrators could prepare
Teams could inventory the EOS and VeloCloud versions they were running. Once the advisories appeared, they would be able to compare their systems with the affected versions and assess updates for their maintenance window.
Arista said publishing the fixes as a group could help customers combine updates into one maintenance window. It also pointed CloudVision customers to the Compliance Dashboard for checking their systems against the advisories. Arista’s explanation gives more background.
The advance notice did not provide enough detail to recommend a particular release. Readers checking current exposure should consult Arista’s advisory page for the published bulletins and later updates.