Resolving LOGO! 0BA8 FS04 Firmware Requirement for CMR2020 BIT VM

David Krause11 min read
PLC HardwareSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Details

The Siemens LOGO! 0BA8 series (sold as LOGO! 8 Basic Modules) added a cellular SMS interface through the LOGO! CMR2020 and CMR2040 communication modules. Beginning with CMR2020/CMR2040 firmware V2.0, the SMS command set was extended to allow direct manipulation of individual bits inside the LOGO! Variable Memory (VM) area using the new value type BIT.

The release notes of the CMR V2 firmware state:

"VM signals of type BIT can now be used. To use a VM tag of type BIT, a LOGO! Basic Module Version 8.1 or higher must be used. Exemplary SMS syntax: Password; LOGO = VM1.3,1, BIT"

When an installer attempts this syntax on an older LOGO! 0BA8 Basic Module, the SMS is silently rejected or returns a parser error from the CMR module. The root cause is not a defect in the BM or the CMR; it is a Feature State (FS) and firmware mismatch on the LOGO! 0BA8 side.

The single most common error condition is:

  • BM is a 0BA8.Standard with firmware V1.08.xx (FS01, FS02, or FS03).
  • CMR2020 has been upgraded to firmware V2.x.
  • User issues Password; LOGO = VM1.3,1, BIT and the bit is never set.
Critical clarification: "Version 8.1" in the CMR release notes refers to LOGO! Soft Comfort V8.1 (the programming software), not a LOGO! 0BA8 hardware version. The correct hardware requirement is a LOGO! 0BA8 at FS04 or higher with BM firmware V1.81.01 or newer.

Identifying Your LOGO! 0BA8 Feature State

Before changing hardware or firmware, determine the Feature State (FS) of the BM. Three methods are reliable in the field.

Method 1 – Read the on-board firmware version

  1. Power the BM and navigate to LOGO! → Diagnostics → IP/Name → FW Version (or LOGO! → Diagnostics → Module → FW on BM with operator panel).
  2. Read the firmware string. The first two digits of the firmware version encode the FS family:
BM Firmware Feature State BIT VM via SMS
V1.08.01 FS01 Not supported
V1.08.02 FS02 Not supported
V1.08.03 FS03 Not supported
V1.81.01 FS04 Supported (with CMR FW V2.x)
V1.81.02 and later FS04 / FS05 Supported

Method 2 – Read from LOGO! Soft Comfort (online)

  1. Connect the PC to the BM via Ethernet (default IP 192.168.0.1, mask 255.255.255.0) or via the CMR2020 IP bridge.
  2. In LOGO! Soft Comfort, select Tools → Transfer → PC → LOGO! or open Online → Module Information.
  3. The Module Information dialog displays the order number (6ED1 052-xxx08-0BA8), hardware revision (ES = Engineering Sample, FS = Feature State), and the BM firmware build.

Method 3 – Read the type label on the device

Open the BM enclosure flap. The third field printed beneath the Siemens logo encodes the FS:

  • 6ED1052-xxx08-0BA8 – generic 0BA8 identifier.
  • FS:04 or higher printed next to the order number is the hardware FS.
A printed FS04 label only proves the BM hardware was built as FS04. The BM still requires the matching firmware (V1.81.01+) to be installed. Siemens ships FS04 hardware with V1.81.x firmware, but a downgrade is technically possible if a user flashed an older firmware image, so always cross-check the firmware string.

LOGO! 0BA8 Generation, ES, and FS Levels

Siemens uses a two-level identification system on the LOGO! 8 platform:

Code Meaning Typical Implication
ES (Engineering Sample) Pre-release hardware, distributed to OEMs Limited availability, not for production
FS (Feature State) Production hardware revision with frozen feature set Defines which firmware can be flashed and which functions are released

Relevant 0BA8 FS levels for this issue:

  • FS01 – FS03 (firmware V1.08.01 – V1.08.03): Always transfers a full byte to/from the VM area when an SMS is processed by the CMR. Addressing a single bit (e.g., VM1.3) overwrites the entire byte; seven other bits in the same VM byte are therefore lost. This is the core of the FS04 requirement.
  • FS04 (firmware V1.81.01 and newer): Adds single-bit transfer mode. Each bit of a VM byte can be read or written independently through the CMR SMS engine, making the BIT type practical.
  • FS05 (newer firmware in the V1.82.x line): Retains the BIT VM feature and adds further communication diagnostics, energy-meter display pages, and web-editor improvements.

CMR2020/CMR2040 Firmware V2 SMS Syntax

With the CMR at firmware V2.0 or newer and the BM at FS04 or higher, the following SMS forms are accepted.

Read a single bit (output response from CMR)

Password; LOGO? VM<byte>.<bit>, BIT

Example – query VM byte 1, bit 3:

1234; LOGO? VM1.3, BIT

Set a single bit high

Password; LOGO = VM<byte>.<bit>,1, BIT

Example – set VM byte 1, bit 3 to 1:

1234; LOGO = VM1.3,1, BIT

Set a single bit low

Password; LOGO = VM<byte>.<bit>,0, BIT

Example – clear VM byte 1, bit 3:

1234; LOGO = VM1.3,0, BIT

Legacy byte syntax (still supported on FS04+)

Password; LOGO = VM<byte>,<value 0-255>, BYTE

The BYTE syntax must be used on FS01-FS03 because the BIT syntax is rejected by the BM-side parser at that FS level.

Root Cause: Why BIT Type Requires FS04

Inside the LOGO! 0BA8, the variable memory is organized as 8-bit bytes. The BM exposes a byte-oriented VM read/write interface to the Ethernet-based S7 communication stack used by the CMR2020. When the CMR issues a write to a single bit, the BM-side firmware must perform a read-modify-write cycle on the affected byte and place the new bit value into the correct bit position.

BMs at FS01-FS03 implement only the byte-level read and write primitives. The CMR V2 firmware, when it receives a BIT-typed command, attempts to invoke the bit-level primitive on the BM. If the BM responds with a function-not-available error, the CMR drops the SMS and logs a parser error in its internal event log (visible through the CMR WebUI at Diagnostics → Event Log).

FS04 added the bit-level read-modify-write primitive to the BM firmware, eliminating the 7-bit loss that occurred when a byte transfer collided with adjacent user bits in the same VM byte. This is the precise reason the CMR release notes link the BIT feature to a 0BA8 firmware build newer than V1.81.00.

Workarounds for FS01-FS03

If a hardware or firmware change is not possible, the BYTE workaround is fully supported on FS01-FS03. It is the only SMS-side method that respects the byte-granular VM interface of these older BMs.

Setting bit V3.0 high using BYTE syntax

Password; LOGO = VM3,1, BYTE

This writes the decimal value 1 (binary 0000 0001) into VM byte 3, which sets bit V3.0 to high and clears bits V3.1 through V3.7.

Setting bit V3.0 low using BYTE syntax

Password; LOGO = VM3,0, BYTE

This clears the entire byte 3. If any other bit in VM byte 3 was in use elsewhere in the LOGO! program, it will be lost. Plan the program so that each VM byte contains only one bit you intend to control via SMS, or reserve the entire byte for SMS use.

Bitwise mask table for byte-level writes

Target bit Decimal value Hex value SMS command
V3.0 1 0x01 LOGO = VM3,1, BYTE
V3.1 2 0x02 LOGO = VM3,2, BYTE
V3.2 4 0x04 LOGO = VM3,4, BYTE
V3.3 8 0x08 LOGO = VM3,8, BYTE
V3.4 16 0x10 LOGO = VM3,16, BYTE
V3.5 32 0x20 LOGO = VM3,32, BYTE
V3.6 64 0x40 LOGO = VM3,64, BYTE
V3.7 128 0x80 LOGO = VM3,128, BYTE

To set multiple bits in the same byte simultaneously, add the decimal values and write the sum:

LOGO = VM3,5, BYTE (sets V3.0 and V3.2 high: 1 + 4 = 5)
Safety caveat: The BYTE write is not atomic on the BM side relative to the LOGO! scan. If a UDF, network input, or HMI is also writing to the same VM byte, the SMS write can be clobbered by the LOGO! scan within the same cycle. Reserve an unused VM byte for each SMS-controlled bit, and never share that byte with internal logic that writes more often than every 200 ms.

Firmware Upgrade Possibilities

Siemens distributes LOGO! 0BA8 BM firmware as signed image files in the LOGO! Soft Comfort installation tree, typically under C:\Program Files\Siemens\LOGOComfort_8\Firmware\. The files use the extension .upd and are flashed via:

  1. Connect the PC to the BM over Ethernet.
  2. In LOGO! Soft Comfort, choose Tools → Transfer → Firmware Update.
  3. Select the matching .upd file. The tool cross-checks the order number and current FS against the file. If the file targets a different FS, the transfer is blocked.
FS-locked firmware: An FS02 BM cannot be flashed to FS04 firmware. The .upd file is signed with the FS identifier of the target hardware. Siemens has never published a cross-FS flash for the 0BA8 platform because the FS change typically reflects a hardware change (for example, a new Ethernet PHY revision or larger flash chip) that the older BM does not have. A "firmware upgrade" from FS02 to FS04 is therefore not possible in the field. The path forward is hardware replacement.

Hardware Replacement Options

Replace the BM with a current 0BA8 module at FS04 or higher. Order numbers vary by display variant and power input; the following are common catalog numbers for the 0BA8 FS04+ generation:

Order Number Description Display
6ED1052-1CC08-0BA8 LOGO! 8 BM, 24 V DC power supply With display
6ED1052-2CC08-0BA8 LOGO! 8 BM, 24 V DC, pure (no display) Without display
6ED1052-1MD08-0BA8 LOGO! 8 BM, 12/24 V DC With display
6ED1052-2MD08-0BA8 LOGO! 8 BM, 12/24 V DC, pure Without display
6ED1052-1FB08-0BA8 LOGO! 8 BM, 115/230 V AC With display

Confirm the FS string on the device label or in the order confirmation before purchase. For a complete product overview including the LOGO! CMR2020 and CMR2040 communication modules, refer to the Siemens LOGO! 8 product overview PDF and the Siemens LOGO! Basic Modules product page. Distributor stock can be verified through authorized channels such as Mouser Electronics LOGO! Logic Modules category.

Migration checklist

  1. Back up the LOGO! program from the FS01-FS03 BM using LOGO! Soft Comfort (File → Save As).
  2. Identify any VM bits in the program that rely on byte-level sharing; reserve a whole byte per SMS-controlled bit on the new BM.
  3. Power down, swap the BM, and re-apply the program.
  4. Update CMR2020/CMR2040 firmware to V2.x if not already done, and re-pair the SIM card with the new BM Ethernet IP.
  5. Send a test BIT-typed SMS and confirm the response.

Verification

  1. From a mobile phone, send 1234; LOGO? VM1.3, BIT using the configured password.
  2. The CMR replies with a status SMS reporting the current value of bit VM1.3 (0 or 1).
  3. Send 1234; LOGO = VM1.3,1, BIT and check the LOGO! program – the assigned output (or UDF input wired to VM1.3) should energize within one scan cycle.
  4. Send 1234; LOGO = VM1.3,0, BIT and confirm the output de-energizes.
  5. Open the CMR WebUI at Diagnostics → Event Log and confirm no parser errors are logged for the test messages.

If steps 1-5 all pass, the BIT VM SMS path is fully operational. If the CMR silently rejects the message, the BM is still at a pre-FS04 build.

Troubleshooting Matrix

Symptom Likely Cause Action
SMS BIT command silently rejected BM at FS01-FS03 Use BYTE syntax or replace BM with FS04+
CMR returns "parser error" or no response Wrong password or extra spaces in SMS Re-check password; SMS must end with BIT token
Bit set high but does not stay LOGO! program overwrites the VM byte each scan Reserve the entire VM byte for SMS use; do not write to it from the LSC program
CMR replies success but BM does not react CMR IP bridge is pointing to a different BM (multi-BM network) Check CMR configuration under LOGO! BM Connection and verify destination IP
BIT works for read but not write VM byte is in the read-only diagnostics range Choose a VM byte in the user range (typically V0-V850 depending on program)
BYTE write clears other bits unintentionally User expected BIT-typed semantics on FS01-FS03 Migrate to FS04+ BM or restructure program to isolate bits
BM firmware cannot be updated to V1.81.x FS-locked firmware image Hardware replacement required; cross-FS flash is not supported

FAQ

What is the minimum LOGO! 0BA8 firmware version for CMR2020 BIT VM SMS?

LOGO! 0BA8 BM firmware V1.81.01 (Feature State FS04) or newer is required. The "Version 8.1" mentioned in the CMR V2 release notes refers to LOGO! Soft Comfort V8.1, not a BM hardware version.

Can I flash an older 0BA8 BM to FS04 firmware in the field?

No. The FS identifier is locked to the hardware revision. A cross-FS flash (for example, FS02 to FS04) is not supported by Siemens. Replace the BM with a current FS04+ unit.

How do I set a single VM bit on an FS01-FS03 BM via SMS?

Use the legacy BYTE syntax and write a decimal value to the entire VM byte. For bit V3.0 high: Password; LOGO = VM3,1, BYTE. Bit V3.0 low: Password; LOGO = VM3,0, BYTE. Reserve the whole byte for SMS use to avoid clobbering other bits.

Does the CMR2020 firmware V2 change require a new SIM card or new CMR hardware?

No. Firmware V2.x is a free firmware update for any existing CMR2020 or CMR2040 module. Apply the update through the CMR WebUI (Administration → Firmware Update) or via the LOGO! Soft Comfort toolchain.

Where can I confirm the FS and firmware of my installed LOGO! BM?

Three reliable methods: read the firmware version from the on-board menu (LOGO! → Diagnostics), connect with LOGO! Soft Comfort and open Online → Module Information, or read the FS field printed on the BM enclosure label beneath the order number. Cross-check both the FS string and the firmware build before drawing a conclusion.

Back to blog