You need to disable the default page in IIS to resolve a vulnerability.
Any IIS Web Server
In order to configure IIS server [IIS 7 and above] for disabling default page:
403 - Forbidden: Access is denied error, when accessing the default document. However, accessing NFA Console with ‘/ra’ will continue to work without any impact.