Overview: S7-400 Flash Memory Cards and Password Protection
The SIMATIC S7-400 family stores its user program on removable Flash memory cards (F-Cards). The 5 V Flash card 6ES7952-1KM00-0AA0 is a 16 MB card used with S7-400 CPUs to retain the user program, system data, and configuration across power cycles. The block-level password protection that Siemens STEP 7 / SIMATIC Manager offers is bound to the CPU protection level (CPU password) and the know-how protection at the FB/FC/DB block level. These are independent of the memory card itself.
When a field engineer is handed a card that contains a password-protected program, two distinct questions arise:
- Can the password itself be removed?
- Can the card be erased so the CPU boots with an empty project?
For the S7-400, the technical reality is that the password cannot be reverse-engineered from a Flash card without the original STEP 7 project or the original programmer. Siemens does not provide a password-recovery utility for S7-400 Flash cards, and the on-card password store uses a hash that is not exposed through any public STEP 7 / TIA Portal interface. The supported workflow is therefore erasure of the entire card via the field programmer (PG) interface. Erasure is destructive: all user blocks, system data, comments, symbols, and configuration are lost. The CPU must then be recommissioned from a fresh STEP 7 / TIA Portal project, or loaded from a known-good backup.
Memory Card Hardware: 6ES7952-1KM00-0AA0 and S7-400 Card Family
The card referenced in the source thread is the 5 V Flash card with Siemens order number 6ES7952-1KM00-0AA0. The 6ES7952 series is the S7-400 Flash card family. The catalog breakdown is summarized in the table below.
| Order Number (MLFB) | Type | Size | Used With |
|---|---|---|---|
| 6ES7952-1KF00-0AA0 | 5 V Flash | 2 MB | S7-400 CPUs |
| 6ES7952-1KG00-0AA0 | 5 V Flash | 4 MB | S7-400 CPUs |
| 6ES7952-1KH00-0AA0 | 5 V Flash | 8 MB | S7-400 CPUs |
| 6ES7952-1KJ00-0AA0 | 5 V Flash | 16 MB | S7-400 CPUs |
| 6ES7952-1KM00-0AA0 | 5 V Flash | 16 MB (long-life variant) | S7-400 CPUs |
| 6ES7952-1KP00-0AA0 | 5 V Flash | 32 MB | S7-400 CPUs |
| 6ES7952-1KS00-0AA0 | 5 V Flash | 64 MB | S7-400 CPUs |
| 6ES7952-0AF00-0AA0 | RAM | 2 MB | S7-400 CPUs (working memory only) |
Key hardware notes:
- These cards are 5 V parallel Flash cards, not the 3.3 V F-Cards used by S7-300 / S7-1200 / S7-1500. The pinout and erase logic differ; an S7-300 card reader will not accept an S7-400 card.
- The card slots into the S7-400 CPU's battery-buffered card slot or into a Field PG M (such as 6ES7712-.....) equipped with the external programming device adapter for S7-400 cards.
- The card has a mechanical dot indicating pin-1 orientation. The dot must align with the corresponding marking in the PG slot. Forcing a card the wrong way will damage the card and the slot.
What "Password" Actually Means on an S7-400 Card
STEP 7 / SIMATIC Manager (and TIA Portal) implement several distinct protection mechanisms. Confusion between them is the most common cause of "I lost the password" tickets.
| Protection Layer | Scope | Where Stored | Removable Without Password? |
|---|---|---|---|
| CPU password (CPU protection level 1-3) | Restricts read/write of blocks via PG | CPU retentive memory + mirrored to card | No, but cleared on full CPU reset (MRES) |
| Know-how protection (FB/FC/DB blocks) | Blocks compiled with S7-Know-How-Protect | Block header on card | No, requires source or original SCL/STL |
| Serial number binding (S7-300/400) | Ties blocks to specific CPU serial number | Block header on card | No, requires field report |
| Configuration data password (TIA Portal) | Encrypts confidential PLC config in project | Project file in PG, not on card | Yes, see TIA Portal V20 - Deleting passwords for protecting confidential PLC configuration data |
For a card extracted from a CPU, the on-card artifacts are the CPU password hash, the encrypted know-how-protection headers, and the bound serial numbers. The TIA Portal "Configuration data password" is a project-side encryption and does not apply to a card pulled out of an S7-400 — it is listed here only because it is a frequent point of confusion when technicians read Siemens documentation across product generations.
Prerequisites for Erasing an S7-400 Flash Card
Carry out the following before any erase operation. Each prerequisite has a specific failure mode if skipped.
- Backup of any usable data. If you do not yet own the source project, use SIMATIC Manager > File > S7 Memory Card > Read from Memory Card while the card is still accessible. This extracts the offline blocks as they sit on the card. Know-how-protected blocks will still be encrypted, but unencrypted blocks (OB, SFB, SFC) are recoverable.
- Field PG with S7-400 card adapter. A SIMATIC Field PG M (6ES7712-... variants) or any PG with the external S7-400 Flash card programming device is required. Standard USB SD card readers cannot read these cards.
- STEP 7 V5.x or TIA Portal with S7-400 support package. SIMATIC Manager (STEP 7 V5.5 / V5.6 / V5.7) is the recommended tool for S7-400 work; TIA Portal can also manage S7-400 cards with the appropriate HSP.
-
PG/PC interface set to
PC Adapter (MPI) (Auto)or, when working directly through the card slot, the local programming device interface set toInternal. - Physical access to the card with the slot orientation identified. The dot on the card label must face the same direction as the dot/arrow molded into the PG's card slot.
- Documented authorization. Erase operations are non-recoverable. Have the work order, machine ID, and customer sign-off recorded before pressing Delete.
Step-by-Step: Deleting the S7-400 Flash Card via Field PG
The procedure below uses SIMATIC Manager (STEP 7 V5.x) because it remains the most widely deployed tool for S7-400 service. The TIA Portal equivalent path is described in the next section.
- Power down the Field PG and insert the 6ES7952-1KM00-0AA0 card into the external programming device slot. Confirm the dot on the card faces the same direction as the marking on the slot. A misoriented card will not seat fully and can be damaged on insertion.
- Power on the Field PG and allow Windows to enumerate the device. If the card is recognized, the SIMATIC Manager Accessible Nodes view will show a node under the local interface.
- Launch SIMATIC Manager and close any offline project that might lock the same interface. Open File > S7 Memory Card > Delete... from the menu bar. The exact menu path in localized versions is Datei > S7-Speicherkarte > Löschen... in German STEP 7.
- Select the target card from the drop-down list of detected S7 memory cards. The dialog displays the card's serial number, capacity, and the project that is currently stored on it. Verify the part number 6ES7952-1KM00-0AA0 matches the card in your hand.
- Confirm the prompt stating that all data on the card will be erased. The dialog will warn that the operation is irreversible. Click OK.
- Wait for the format/erase to complete. For a 16 MB card the operation typically takes 20-60 seconds. The progress bar must reach 100% before the card is removed.
- Remove the card only after SIMATIC Manager reports the operation as complete. Power down the PG before ejecting the card to avoid mid-write corruption.
- Verify by re-inserting the card and re-opening File > S7 Memory Card > Display.... The card should now show zero blocks and zero bytes used. If the card still shows the previous project, repeat steps 3-6 and verify the dialog was set to Delete rather than Read.
Step-by-Step: Erasing an S7-400 Card via TIA Portal
TIA Portal (V15.1 and later with S7-400 HSP, including V20) supports the same delete operation through the project tree and the card reader view.
- Open the TIA Portal project or create an empty one with the correct S7-400 CPU device.
- From the project tree, right-click the S7-400 CPU and choose Online & Diagnostics.
- Select the Memory group, then Format Memory Card. This action requires a live online connection to the CPU; if the card is in the Field PG, the operation acts on the card through the local programming interface.
- Confirm the prompt. TIA Portal performs a logical format of the card file system and then a verification read.
- After formatting, the card is empty. Re-download the new project or insert the card into the S7-400 CPU to start with a clean boot.
For project-side password management (such as the "Password to protect the PLC configuration data" function), refer to the official Siemens TIA Portal V20 documentation: Deleting passwords for protecting confidential PLC configuration data. This document covers the project-encryption password that is set in the TIA Portal project tree, not the CPU password stored on the Flash card; clearing it requires either the current password or full re-creation of the project.
Alternative: MRES on the S7-400 CPU
If the card can be reinserted into the same S7-400 CPU it came from, a CPU memory reset (MRES) clears the CPU's working memory and the password stored in retentive system data. The MRES procedure is:
- Set the mode switch to
STOP. - Hold the MRES button and rotate the mode switch through
MRESand back toSTOP. The CPU'sSTOP,RUN, andSFLEDs cycle; release the button when onlySTOPremains lit. - After MRES, the CPU is in a clean state. If the card is still installed, the CPU will re-read it on the next power-up; if the card still contains a password-protected program, the CPU will again prompt for the password on the next online attempt. MRES therefore solves the on-CPU password, not the on-card password.
The combination that fully clears a system is: (a) erase the card via the Field PG as described above, (b) perform MRES on the CPU, and (c) reload a new project from STEP 7 or TIA Portal. Only then is the system in a known-clean state with no residual password binding.
Why S7-400 Differs from S7-300 on Card Passwords
The S7-300 series uses a different Flash card format (MMC, 3.3 V, 6ES7953-....) and historically has had third-party utilities published that attempt to clear the CPU password by manipulating the MMC file system. S7-300 cards do not store the same protection headers, and the CPU performs less strict validation of the system data blocks at boot.
S7-400 is fundamentally different:
- The CPU validates the system data blocks (SDBs) against a checksum that includes the protection fields. A corrupted SDB causes the CPU to refuse to enter RUN.
- The 5 V parallel Flash interface does not present itself as a standard block device to the host, so generic Flash utilities cannot be used to bypass the file system.
- Siemens does not document a public tool that can read or write the SDBs on an S7-400 card outside the STEP 7 / TIA Portal software stack.
The practical consequence is that "remove password from S7-400 card" is not a supported workflow. The supported workflow is "erase the card and reload from a project you have authorization to use."
Verification Procedures After Card Deletion
Before reinstalling a freshly erased card into a production S7-400 CPU, run the following checks:
- Card contents check. Re-insert the card in the Field PG, open SIMATIC Manager > File > S7 Memory Card > Display.... The dialog should show zero user blocks and zero system blocks. If any blocks appear, the erase did not complete and the card must be re-erased.
- Card capacity check. The display should still report the full nominal capacity of the card (16 MB for 6ES7952-1KM00-0AA0). A reduced capacity indicates that the Flash Translation Layer has flagged bad blocks — the card is at end of life and should be replaced.
-
CPU boot test. Insert the card into the target CPU, power up, and observe the LED pattern. Expected:
STOPsolid, noSF, noBF. If the CPU showsSF, the system data on the card is inconsistent and the card must be re-erased. - Project download test. With the empty card in place, download a known-good test project (a single OB1 with no I/O references) to confirm the CPU-to-card write path is functional before re-installing in the running process.
Troubleshooting Matrix
| Symptom | Likely Cause | Corrective Action |
|---|---|---|
| SIMATIC Manager does not list the card in S7 Memory Card > Delete | Card inserted upside-down, wrong card type (e.g., 3.3 V MMC), or PG adapter not detected | Re-seat with dot aligned; confirm MLFB starts with 6ES7952; reinstall PG adapter driver |
| Delete operation reports "Card write-protected" | Mechanical write-protect switch on the card is engaged (legacy 5 V cards have one) | Slide the write-protect switch to the unlocked position |
| Delete completes but card still shows old project on re-display | STEP 7 read cached the previous listing | Close and re-open the S7 Memory Card > Display dialog; verify card serial number |
| CPU shows SF after erased card inserted | Card has corrupt SDBs from interrupted erase | Re-erase the card in the PG; if SF persists, replace the card |
| Field PG cannot read the 5 V card at all | Wrong reader or no S7-400 HSP installed | Use only the S7-400 external programming device; install the S7-400 HSP in TIA Portal |
| PG locks up during erase | Battery low on PG or card contact issue | Replace PG battery, clean card contacts with isopropyl alcohol, retry |
| Card reports reduced capacity (e.g., 12 MB instead of 16 MB) | End-of-life Flash, bad block remapping active | Replace card; transfer program to a new 6ES7952-1KM00-0AA0 (or larger) |
Best-Practice Recommendations for S7-400 Card Lifecycle
- Treat every Flash card as the only copy of the program. Maintain a current STEP 7 / TIA Portal project archive on a network share or version control system, with a copy offline. The card is the runtime copy; the archive is the source of truth.
- Store the CPU password in a password manager tied to the asset. Loss of the password is functionally equivalent to loss of the source code for know-how-protected blocks.
- Document the card orientation in the maintenance procedure. The "dot" mark is the only visual indicator on 5 V cards and is easy to misread in poor lighting.
- Audit card age. 5 V Flash cards have a limited write endurance. For applications with frequent online changes, replace cards every 5-7 years as preventive maintenance. Use the next-larger capacity variant when scaling up to reduce write amplification.
- Label cards with the asset tag and the date of last program change. This avoids the situation in which an unknown card is pulled from a drawer and nobody knows which machine it belongs to.
FAQ
Can the password be recovered from an S7-400 Flash memory card?
No. Siemens does not publish a password-recovery procedure for S7-400 cards, and the on-card hash cannot be reversed through STEP 7 or TIA Portal. The supported recovery path is to contact the original programmer, request the source project, or — as a last resort — erase the card via a Field PG using SIMATIC Manager > File > S7 Memory Card > Delete... and reload from a known-good project.
What is the part number for the 5 V 16 MB S7-400 Flash card referenced in service tickets?
The 6ES7952-1KM00-0AA0 is a 16 MB 5 V Flash card for the S7-400 family. The earlier 6ES7952-1KJ00-0AA0 is also 16 MB but with a shorter service-life rating. The current long-life 5 V card for S7-400 is 6ES7952-1KM00-0AA0; for 32 MB use 6ES7952-1KP00-0AA0.
Which way does the card go into the Field PG?
The dot printed on the card label must align with the dot or arrow molded into the card slot of the Field PG (typically the upper-left corner of the slot). Forcing a misoriented card will bend the contacts and damage both the card and the slot.
Does erasing the card also remove the CPU password?
The card-format operation removes the password hash from the card's system data blocks. After the card is reinserted in a CPU, however, the CPU retains its own copy of the password in retentive memory. To clear the CPU password, perform a CPU memory reset (MRES) with the mode switch on the S7-400 CPU. Both operations — card erase plus MRES — are required to fully clear a system.
Is the TIA Portal "configuration data password" the same as the CPU password?
No. The TIA Portal "Password to protect the PLC configuration data" is a project-side encryption that protects the offline project in TIA Portal; it does not apply to a card pulled from a running S7-400. The CPU password is a runtime protection level that lives in the SDBs on the card and in the CPU's retentive memory. The TIA Portal V20 documentation at docs.tia.siemens.cloud describes only the project-side password workflow.