But if it was 3, why not say "I know there is a vulnerability, but I can't share the details"?
I'm not saying it isn't 3, but if it is, it seems like there might be more to it than a run-of-the-mill CVE.
Or maybe she doesn't know of a specific vulnerability/backdoor but has some reason to be suspicious there might be.