Resolving S5-115U 'FB Exists in EPROM' Block Transfer Failure

David Krause21 min read
PLC HardwareSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Resolving S5-115U “FB Exists in EPROM” Block Transfer Failure

When modifying a Function Block on a running SIMATIC S5-115U (CPU 943B with SINEC L2 interface) under STEP 5, the programming device returns the prompt FB1: exists in EPROM. Continue? followed by 0 blocks transferred. Pressing either Yes or No aborts the transfer; the modified FB never reaches the controller. The standard Compress memory function in STEP 5 does not clear the condition. The error is not a defect in the project, the PG cable, or the CPU firmware; it is a direct consequence of the bit-cell technology of the installed memory submodule. This article maps the S5-115U memory architecture, isolates the EPROM-as-write-target root cause, and walks through three field-proven resolution procedures that preserve the existing program and the system data.

Symptom snapshot. Block → Transfer → PLC produces FB1: exists in EPROM. Continue?. User answers Yes. Status line shows 0 blocks transferred. The cyclic program is unchanged. Compress memory returns without error but the next transfer still fails.

1. Problem Summary

The user-facing sequence is reproducible across STEP 5 V6.x and V7.x and is independent of the online/offline mode of the programming device (PG):

  1. Open the STEP 5 project, select the FB to edit, and complete the source edit.
  2. Choose Block → Transfer → PLC (or click the PC → AG icon in the toolbar).
  3. STEP 5 issues the prompt FB1: exists in EPROM. Continue?.
  4. The user answers Yes. STEP 5 issues 0 blocks transferred.
  5. The CPU's cyclic program is unchanged. OB1, FB1, PB and DB blocks remain in the previous image.

The CPU emits the prompt because it has detected that the destination memory for the FB is a submodule in the EPROM slot, not the working RAM. The CPU can read the EPROM at every cycle scan, but it cannot toggle the floating-gate bits in-circuit. STEP 5 surfaces the prompt as a guard so the engineer is not misled into thinking the transfer succeeded when the FB has not actually been overwritten.

2. SIMATIC S5-115U Memory Architecture

The S5-115U is a modular PLC with a single memory submodule slot on the CPU front plate. The slot accepts one submodule from one of three families (see the SIMATIC S5-115U Automation System manual, indexed at the Siemens Industry Online Support):

  • RAM (6ES5 371-series) — volatile read/write, requires battery backup.
  • EPROM (6ES5 372-series) — UV-erasable, read-only at runtime, programmable in a standalone prommer.
  • EEPROM (6ES5 374-series) — electrically erasable, can be rewritten in-circuit through the CPU.

The CPU has a small working RAM scratch area for the stack, process-image I/O, and bit flags, but the user program (OB, PB, FB, DB, SB, FX) and the system data (SD) live in the submodule. The Continue? prompt is generated when STEP 5 attempts a write and the CPU reports that the destination block address maps into the EPROM device. The PG then refuses to mark the block as transferred. This is consistent with the documented block-transfer behavior of the S5-115U CPU 94x series.

Architecture point. The CPU has no manual “force write” command for an EPROM block. The block directory is reconstructed at every cold start by scanning the submodule. There is no “unlock EPROM” sequence in STEP 5.

3. Memory Submodule Identification Catalog

The table below summarizes the most common S5-115U submodules shipped by Siemens. Verify the MLFB (Machine-Readable Product Designation) on the side of the module label before assuming a technology class. The third character of the 6ES5 37x designation is the technology indicator: 1 = RAM, 2 = EPROM, 4 = EEPROM.

MLFB Type Capacity Erasure Method In-Circuit Write Notes
6ES5 371-0LA11 RAM 16 KB Battery removal Yes No on-card backup
6ES5 371-0MA11 RAM 32 KB Battery removal Yes No on-card backup
6ES5 371-1LA11 RAM 16 KB Battery removal Yes On-card lithium backup
6ES5 371-1MA11 RAM 32 KB Battery removal Yes On-card lithium backup
6ES5 372-0LA11 EPROM 16 KB UV light, ~30 min No Ceramic, quartz window
6ES5 372-0MA11 EPROM 32 KB UV light, ~30 min No Ceramic, quartz window
6ES5 372-1LA11 EPROM 16 KB UV light, ~30 min No 5 V-only variant
6ES5 372-1MA11 EPROM 32 KB UV light, ~30 min No 5 V-only variant
6ES5 374-0LA11 EEPROM 16 KB Electrical, in CPU Yes ~10,000 write cycles per block
6ES5 374-0MA11 EEPROM 32 KB Electrical, in CPU Yes ~10,000 write cycles per block
6ES5 374-1LA11 EEPROM 16 KB Electrical, in CPU Yes Faster page mode
6ES5 374-1MA11 EEPROM 32 KB Electrical, in CPU Yes Faster page mode
6ES5 374-2LA11 EEPROM 16 KB Electrical, in CPU Yes With battery backup
6ES5 374-2MA11 EEPROM 32 KB Electrical, in CPU Yes With battery backup

Visual identification: EPROM modules (6ES5 372) carry a quartz window under a paper or foil sticker; this is the UV-C erasure aperture. EEPROM modules (6ES5 374) are usually opaque and labeled “EEPROM” on the side; the absence of a quartz window is the visual confirmation. If the quartz window is covered with a UV-opaque sticker, the cover is in place; if the window is clear, the module has either been erased or has never been programmed.

4. EPROM, EEPROM, and RAM: Bit-Cell Behavior

The functional difference is in the floating-gate transistor that stores each bit. The S5-115U memory submodules use three different cell technologies:

  • SRAM (6ES5 371). A six-transistor cell. The bit is held in a cross-coupled latch. Read and write both require only Vcc on the word line. The on-card or CPU-holder lithium battery preserves the latch state through power-down. Battery life is 1–5 years depending on temperature and self-discharge of the cell.
  • EPROM / FAMOS (6ES5 372). Floating-gate Avalanche-injection MOS. Programming is done by applying a high drain-source voltage (typically 12.5 V to 21 V) to inject hot electrons into the floating gate. The cell can only be reset by exposing the silicon die to UV-C light at 253.7 nm for 20–30 minutes; UV photons discharge the floating gate by photo-emission. The CPU cannot produce 12.5 V at every memory address in-circuit, and it cannot supply UV light, so the EPROM is write-protected at runtime.
  • EEPROM / FLOTOX (6ES5 374). Floating-gate Tunnel Oxide. Programming and erasure both use Fowler-Nordheim tunneling at ~20 V, generated on-chip by a charge pump. The CPU issues a 5 V command and the on-chip charge pump handles the high voltage locally. The result is a cell the CPU can rewrite thousands of times, with each cell rated for ~10,000 to 100,000 cycles before wear-out.

This is the technical reason the CPU can refuse FB writes. It is not a software lock; it is a physical impossibility for the EPROM device to accept a write from a 5 V logic signal on the standard S5 backplane. Only the on-card charge pump of an EEPROM (or the standalone prommer for an EPROM) can supply the programming voltage.

5. Root Cause Analysis: Why the CPU Refuses the Write

When the user selects Transfer → PLC in STEP 5, the PG sends a write command over the serial MPI/AS511 or the SINEC L2 channel. The CPU's loader receives the block payload and consults its block directory, which is mirrored from the submodule on cold start. The directory records each block's address, length, and the submodule partition it occupies. If the block address falls inside the EPROM address range, the loader returns a block is in EPROM status. STEP 5 translates that into the FB1: exists in EPROM. Continue? prompt.

The Compress memory function only moves blocks within the working RAM partition; it cannot relocate blocks out of an EPROM partition because the EPROM cells cannot be rewritten. This is why compress fails to clear the condition. The Delete block function is similarly blocked: STEP 5 will report block in EPROM and refuse.

The diagnostic decision flow is:

STEP 5: Transfer FB to PLC "FB1 exists in EPROM. Continue?" Check module MLFB label 6ES5 372 6ES5 371 / 374 EPROM detected UV erasure only CPU cannot write RAM / EEPROM detected In-circuit write OK Confirm overwrite Path B or C UV-erase EPROM, program in prommer, or replace with 6ES5 374 EEPROM Path A Transfer FB, compare PG ⇄ PLC, warm restart CPU mode switch

6. Symptom Matrix and Diagnostic Decision Tree

Symptom Observed Most Likely Cause First Action
FB exists in EPROM. Continue? then 0 blocks transferred EPROM submodule installed Check MLFB on module label
Prompt does not appear, FB is rewritten cleanly RAM or EEPROM submodule installed Verify block checksum in PG
Prompt appears only on cold start, clears after warm restart Battery dead on RAM module Replace lithium battery, verify holder voltage
STEP 5 reports block in passive submodule Wrong submodule slot selected as active Move project to active submodule slot
Write error 7x0A in status line EEPROM write-cycle exhaustion Replace EEPROM with 6ES5 374 spare
FB writes, then disappears on next power-up RAM module without functional battery Fit battery-backed RAM (6ES5 371-1L/M) or replace with EEPROM
CPU goes into STOP after transfer Block checksum error in modified FB Recompile FB in STEP 5, retransfer
Transfer hangs for >30 s then fails No active submodule; CPU working RAM only Insert RAM/EEPROM submodule with project

7. Resolution Path A — In-Circuit Write with RAM or EEPROM

If a RAM (6ES5 371) or EEPROM (6ES5 374) module is installed, the CPU can rewrite the block in-circuit. This is the simplest path and requires no module removal.

7.1 Prerequisites

  • STEP 5 V6.x or V7.x installed on the PG (PG 720, PG 740, PG 760, or compatible PC with AS511 USB converter).
  • PG connected to the CPU via AS511 (COM1 serial at 9600 baud, 15-pin sub-D) or via SINEC L2 (9-pin sub-D to PROFIBUS cable).
  • CPU in RUN or RUN-P mode. STOP mode is acceptable for transfer; RUN-P allows online status while editing.
  • Verified battery backup on the CPU holder (3.6 V lithium, ~1.5 Ah). Use a holder such as the 6ES5 980-0AE11 or equivalent. Voltage should measure >3.4 V across the holder terminals with the CPU powered down.

7.2 Procedure

  1. In STEP 5, open the project. Confirm the FB source code is correct and compiles cleanly with Block → Edit → Generate (or Block → Compile in older releases).
  2. Select Block → Transfer → PLC. The transfer dialog lists the blocks to transfer. Deselect any blocks you do not want to overwrite.
  3. Click Transfer. If the prompt FB1: exists in RAM/EEPROM. Overwrite? appears, click Yes.
  4. STEP 5 returns 1 block transferred in the status line. If it returns 0 blocks transferred, return to Section 6 (Symptom Matrix) and re-diagnose.
  5. From the PG, select Block → Compare → PG ⇄ PLC to verify byte-for-byte equality. The result should be blocks identical.
  6. Trigger a warm restart by toggling the CPU mode switch: RUN → STOP → RUN. The CPU re-loads the modified block from the submodule into the working RAM.
  7. Confirm the new FB is in use by selecting Block → Status (F9 in STEP 5 V6.x) and stepping into FB1 with the process running.

7.3 Verification

  • PG status line shows blocks identical after the compare.
  • CPU's cyclic scan uses the new FB code. Confirm with a status block or breakpoint.
  • The new FB persists across a power cycle (cold start), which proves the write landed in the non-volatile partition of the submodule.

8. Resolution Path B — Remove EPROM, Erase with UV, Program Externally, Reinsert

When an EPROM is the only submodule available, in-circuit write is impossible. The standard field procedure is to remove the EPROM, erase it with UV-C light, program it in a standalone prommer, and reinsert it.

8.1 Prerequisites

  • UV-C EPROM eraser with 253.7 nm lamp. Common field units: WILLETT, Stag, BPM, Elnec, or the older Siemens 6ES5 898 eraser.
  • Standalone EPROM prommer compatible with 27C256 / 27C512 pinout: e.g. HiLo ALL-11, Data I/O Unisite, BPM Micro, or Elnec BeeProg.
  • STEP 5 project file exported to a hex or S-record format. Common formats: SINEC L2 HEX, MOTOROLA S-record, INTEL HEX. The prommer software imports the S-record or HEX file directly.
  • Antistatic wrist strap, EPROM extraction tool, and a conductive foam mat for the removed module.
  • A documented, versioned backup of the existing project on the PG hard disk and on an external medium.

8.2 Procedure

  1. Export the full STEP 5 project to disk: File → Export → S5 file. Save the system data (SD) as a separate file. Record the export date and version.
  2. Power down the S5-115U rack. Open the front cover of the CPU 943B. Confirm the rack is de-energized before touching the module.
  3. Discharge yourself with the wrist strap. Use the EPROM extractor to remove the memory submodule from the slot. Place the module on a conductive foam mat, quartz window facing up.
  4. Verify the silicon identifier on the module label (e.g. 27C256, 27C512). Match this to a compatible prommer socket adapter.
  5. Place the module in the UV eraser. Close the lid. Erase for 25–35 minutes at 253.7 nm. Typical flux is ~15 mW/cm² at the lamp surface. Do not stack modules; one per eraser tray.
  6. Verify erasure by reading the EPROM in the prommer. All bytes must read 0xFF. If any byte is not 0xFF, re-erase for another 15 minutes. Cumulative UV exposure beyond ~2 hours begins to degrade the oxide and shorten retention.
  7. In STEP 5, edit the FB source. Save the project. Re-export to a fresh S-record/HEX file. The modified FB1 will be included.
  8. Program the EPROM with the prommer. Include the full set of blocks: OB1, OB21, OB22, OB31, OB34, all PBs, all FBs (including the modified FB1), all DBs, and the system data (SD).
  9. Verify the EPROM in the prommer: read back and checksum-compare with the source. The prommer will report a list of mismatched addresses; resolve any mismatches before reinserting.
  10. Reinsert the EPROM into the CPU 943B submodule slot. The keying notch must align with the slot key. The module is keyed to prevent reverse insertion, but verify pin 1 orientation against the silk-screen legend.
  11. Power up the rack. The CPU performs a cold start, copies the EPROM image into working RAM, and begins cyclic scanning.
  12. Connect the PG and run Block → Compare → PG ⇄ PLC. The result should be blocks identical.
UV-C hazard. UV-C light at 253.7 nm is harmful to skin and eyes. Use a closed eraser and avoid direct exposure. Do not look at the lamp while the eraser is open. Field engineers have reported mild photokeratitis after accidental exposure.

8.3 Verification

  • The PG shows the new FB1 source code after the compare.
  • The CPU enters RUN and the process responds to inputs per the new logic.
  • A second cold start (power down, power up) still shows the new FB1. This confirms the EPROM holds the modified image across power cycles.

9. Resolution Path C — Replace EPROM with EEPROM

If the user plans to do further in-circuit edits, the best long-term fix is to swap the EPROM for an EEPROM of equal or greater capacity. The 6ES5 374 EEPROM is pin-compatible with the 6ES5 372 EPROM in the CPU 943B slot, so the swap is mechanical.

9.1 Procedure

  1. Identify the existing EPROM capacity from the MLFB. 6ES5 372-0Lxxx = 16 KB. 6ES5 372-0Mxxx = 32 KB.
  2. Order a matching EEPROM: 6ES5 374-0LA11 (16 KB) or 6ES5 374-0MA11 (32 KB) for a like-for-like replacement. For larger projects, the 6ES5 374-1Mxxx (32 KB fast page) or 6ES5 374-2Mxxx (32 KB with battery backup) is preferred.
  3. With the EPROM removed, fit the EEPROM into the same slot. Pin 1 orientation is identical to the EPROM module.
  4. Cold-start the CPU. The loader copies the EPROM image into the new EEPROM's working area on the first scan.
  5. Connect the PG, transfer the modified FB1 to the PLC using Path A. The CPU's loader now writes directly into the EEPROM cells via the on-chip charge pump. No UV erasure is required.
  6. Note the EEPROM write-cycle budget: ~10,000 to 100,000 cycles per block. The CPU increments an internal wear counter; if the cycle budget is exhausted, subsequent writes will fail with a write error (typically 7x0A). Plan module rotation if the application does many online edits per week.

9.2 Verification

  • The PG transfer completes with 1 block transferred.
  • After a power cycle, the modified FB1 is still present. This proves the EEPROM held the write non-volatilely.
  • Compare against a known-good PG copy: blocks identical.

10. CPU 943B and SINEC L2 Specific Notes

The CPU 943B is a member of the S5-115U 943-series, with a 16-bit internal bus, 48 KB address space, and a built-in SINEC L2 interface. Two specific behaviors matter for this issue:

  • SINEC L2 transfer path. The SINEC L2 interface on the CPU 943B uses the same internal bus as the memory submodule for block transfer commands. If the EPROM is the destination, the L2 stack will return the same block in EPROM status as the AS511 path. The transfer route (serial AS511 vs. SINEC L2) is not the cause of the failure; the destination technology is.
  • Block directory rebuild. The CPU 943B's block directory is reconstructed at every cold start by scanning the memory submodule. There is no manual “unlock” command for an EPROM block at the CPU side. The only way to make a block writable is to physically replace the submodule (Path C) or to change the storage technology of the existing module (Path B).

For users on a CPU 944 or CPU 945, the same memory submodule rules apply. The only difference is the larger address space and the AG automation computer extensions; the EPROM/EEPROM/RAM distinction is unchanged. The SIMATIC S5-115U product family is described in detail in the system manual indexed at the Siemens Industry Online Support; the SIMATIC S5 successor page at www.siemens.com/s5 documents the lifecycle status of the family.

11. Battery Backup, Cold Start, and Data-Loss Risk

Removing a battery-backed RAM or EEPROM submodule will cause data loss if the backup battery is the only retention source. Plan accordingly.

  • RAM modules with on-card backup. The 6ES5 371-1L/M variants carry a soldered lithium cell that holds the bit cells through power-down. The cell is rated for 1–5 years at 25 °C. Removing the module without the cell installed (or with a dead cell) clears the program on insertion into the rack.
  • CPU holder battery. The CPU 943B holder (e.g. 6ES5 980-0AE11) carries a 3.6 V lithium cell that holds internal flags, the process image, and timer/counter values through short power outages. The holder battery does not retain the user program; the user program lives in the submodule. The holder battery voltage should be measured every 12 months and replaced at <3.0 V.
  • Cold start behavior. A cold start (OB20) erases the working RAM and remaps blocks from the submodule. After a cold start, the PG should immediately reload any temporary or process-specific DBs (e.g. recipe data) that were not stored in the submodule.
  • EEPROM write-cycle budget. The 6ES5 374 EEPROM is rated for ~10,000 to 100,000 write cycles per cell. A typical online edit of one FB writes a small number of cells; the budget is not a practical limit for monthly edits. The limit is relevant for high-cycle applications such as recipe downloads in batch processes.

11.1 Risk-Mitigation Checklist

  • Export the full STEP 5 project to a backup folder before any physical module work.
  • Save the system data (SD) separately. The SD is the block that holds the PG-to-PLC configuration, the IP/baud settings for SINEC L2, and the process-image map. The SD is easy to lose and expensive to recreate.
  • Record the MLFB of the existing module for the replacement order. The label is on the side of the ceramic or PCB.
  • Have a known-good spare EPROM/EEPROM on the shelf. The 6ES5 374-0LA11 / -0MA11 modules are still orderable through Siemens spares channels for the S5 lifecycle.
  • Photograph the module orientation and the slot keying before removal.

12. Verification Checklist

After any of the three resolution paths, run this checklist to confirm the fix.

  • PG → Block → Compare → PG ⇄ PLC reports blocks identical for the modified FB.
  • CPU is in RUN and not in STOP with diagnostic interrupt.
  • Cyclic scan executes the new FB code. Confirm with STEP 5 Status Block (F9 hotkey in STEP 5 V6.x).
  • Power-cycle the rack: cold start, warm start, then RUN. The new FB must persist.
  • If the new FB uses symbols, confirm the symbol table (Symbols.s5d) is in the same submodule partition as the FB.
  • Save the project to a versioned folder. Use STEP 5's DOKUMENT output for an as-built record.
  • Note the new MLFB and write-cycle count in the plant asset register. This is the right place to flag the module for future replacement.

13. Field-Engineering Notes and Edge Cases

13.1 Mixed-Partition Submodules

Some S5-115U projects use two submodules: an EPROM for the cold-start program and a RAM for online DBs. In this configuration, the OB1, FBs, and PBs sit in the EPROM and the DBs sit in the RAM. The Continue? prompt will appear only for blocks in the EPROM partition. The CPU's block directory reports the partition in the STEP 5 Memory Configuration screen (under Block → Memory → Configuration in some STEP 5 versions). Verify the partition map before assuming the whole program is in EPROM.

13.2 Cold Start with Wiped Battery

If the CPU holder battery has been removed and the RAM submodule is unbacked, a cold start will return the CPU to its factory-default state with no user program. In this condition, the CPU will accept a full project transfer from the PG because there is no EPROM block to clash with. The FB exists in EPROM prompt will not appear, because no FB exists yet. Use this as a recovery: if the EPROM is broken or missing, fit a RAM submodule, replace the holder battery, and reload the project from the PG backup.

13.3 Block Header Corruption

STEP 5 records the block length and the block type in a 4-byte header at the start of each block. If the EPROM has been partially erased (UV exposure insufficient), the header may be 0xFF in some bytes and original in others. STEP 5 may interpret the partial header as a valid but very long block and refuse to overwrite it. The diagnostic is a STEP 5 Block → Directory listing that shows FB1 with a length many times larger than the source. The fix is full UV erasure of the EPROM and a clean reprogram.

13.4 Serial Cable vs. SINEC L2 Cable Pinout

The AS511 cable is a 15-pin sub-D to 25-pin sub-D on older PGs (PG 720/730) and a 9-pin sub-D to 15-pin sub-D on newer PGs. The SINEC L2 cable is a 9-pin sub-D to 9-pin sub-D with PROFIBUS termination. Do not substitute one for the other; the voltage levels and pin assignments differ. A mismatched cable can damage the PG or the CPU interface.

Why does the S5-115U say “FB exists in EPROM” if I never changed the memory?

The prompt is generated by the CPU each time STEP 5 attempts a write to a block whose address falls inside the EPROM partition. It is not a flag that was set once; it is a real-time check on the destination technology. If you have always used an EPROM submodule, every FB edit triggers the prompt. To remove the prompt permanently, replace the EPROM (6ES5 372) with an EEPROM (6ES5 374) of equal or larger capacity; the EEPROM is in-circuit writable and the prompt will not appear.

Can I convert an EPROM to an EEPROM in-circuit without removing the module?

No. The S5-115U memory submodule is a discrete hardware device with its own silicon die. The technology class (EPROM FAMOS, EEPROM FLOTOX, or SRAM) is fixed at the die level. There is no electrical sequence that turns an EPROM cell into an EEPROM cell. The only ways to make a block writable are (a) replace the submodule with an EEPROM or RAM, (b) UV-erase the EPROM and reprogram it in a standalone prommer, or (c) load a different project into a RAM submodule while leaving the EPROM in place as a boot image.

Does the S5-115U CPU 943B support online FB edits through SINEC L2?

Yes, the CPU 943B's built-in SINEC L2 interface supports online block transfer, status, and variable monitoring. The L2 stack and the AS511 stack share the same CPU-side block-transfer handler, so an EPROM block returns the same block in EPROM status regardless of the physical interface. Online FB edits through SINEC L2 will succeed only if the destination block is in a RAM or EEPROM partition; the network medium does not change the underlying write semantics.

How do I identify whether my S5-115U submodule is EPROM, EEPROM, or RAM?

Read the MLFB on the side label. A 6ES5 371-xxx is RAM, a 6ES5 372-xxx is EPROM, and a 6ES5 374-xxx is EEPROM. Visually, an EPROM module has a quartz window under a sticker (the UV erasure aperture); an EEPROM module is usually opaque and labeled “EEPROM”; a RAM module has a lithium cell socket or a soldered cell. When in doubt, remove the module with the rack powered down and read the label against the catalog in Section 3.

What write cycles are typical for the 6ES5 374 EEPROM module?

The 6ES5 374 EEPROM is rated for ~10,000 to 100,000 write cycles per cell, depending on the variant. The 6ES5 374-0L/M and -1L/M variants are at the low end (~10,000 cycles). The -2L/M variants (with battery backup) extend the practical life by adding a RAM overlay, which absorbs frequent writes. For an application with one FB edit per month, the budget is not a practical limit. For a batch application that downloads recipes every 5 minutes, plan module rotation at ~5 years.

Back to blog