Siemens LOGO! Program Recovery: FBD Upload Without Software

David Krause15 min read
HMI ProgrammingSiemensTutorial / How-to
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

Recovering a control program from a deployed Siemens LOGO! controller without the original project file forces a specific set of decisions: obtain the correct PC cable, install the correct generation of LOGO! Soft Comfort, accept the on-device FBD-only editing limit, and recognize that password protection or a red (program-disabled) memory card will defeat every recovery path. This reference covers the practical workflow for the LOGO! 24, 8DI(4AI)/4DO, 200-block module with ordering code 6ED1052-1CC00-0BA6 (LOGO! 12/24RCE generation) and clarifies what an engineer can and cannot do without the original engineering software and cable.

Hard constraint: No version of LOGO! Soft Comfort can download, decode, or decompile a LOGO! program without a compatible physical or Ethernet connection to the controller. Memory-card transfer of the project (not just the boot image) requires a Siemens LOGO! memory card that is not write-protected and that has been formatted inside the same controller family.

Hardware Identification: LOGO! 6ED1052-1CC00-0BA6

Before any recovery attempt, verify the exact module on the machine. The string 6ED1052-1CC00-0BA6 decodes as follows in the Siemens MLFB scheme:

MLFB segment Meaning
6ED1 LOGO! product family
052 Compact module, 8 digital inputs (4 of which are analog-capable) / 4 digital outputs, no analog outputs
1 Display version (integrated 6-line text display + cursor keys)
CC Power 12/24 V DC; outputs are relay 5 A
00 Screw-type terminals
0BA6 Hardware platform (sixth LOGO! generation, "0BA6"), 200 function blocks, no Ethernet

The 0BA6 suffix is the critical discriminator. It tells the engineer which generation of cable and software to procure:

Generation Typical MLFB suffix Programming cable Soft Comfort version Ethernet
0BA0–0BA5 0BA0…0BA5 LOGO! PC cable (RS-232, 6ED1057-1AA00-0BA0) V1.0 – V6.1 No
0BA6 0BA6 LOGO! USB PC cable (6ED1057-1AA01-0BA0) V7.x – V8.x No
0BA7 / 0BA8 0BA7 / 0BA8 LOGO! USB PC cable (6ED1057-1AA01-0BA0) V8.x No (still serial)
0BA8 Standard (with Ethernet) 0BA8 Std Standard Ethernet patch cable V8.1+ Yes
0BA9 / current — Ethernet patch cable LOGO! Soft Comfort V9 Yes

For 6ED1052-1CC00-0BA6, the correct cable is the LOGO! USB PC cable, order number 6ED1057-1AA01-0BA0. The older RS-232 cable 6ED1057-1AA00-0BA0 will not be recognized by a 0BA6 module and may damage the RS-232 port on legacy PCs.

Program Storage and Memory Architecture

Internally, a LOGO! 0BA6 stores exactly one program in non-volatile EEPROM. There is no source-vs-runtime distinction as found in a S7-1200/1500. The program is held as a compiled, proprietary block graph that is functionally equivalent to a Function Block Diagram (FBD) representation. The compiled graph is not a structured text source file, not a ladder list, and not a SCL/ST archive — it is the result of FBD/UDT compilation by LOGO! Soft Comfort.

Consequences for recovery:

  • On-device edit always presents the program as FBD, regardless of the editor mode used in Soft Comfort. The text display cannot show a true IEC 61131-3 ladder diagram.
  • A round-trip upload → save → edit in Soft Comfort returns the program in FBD. If the original was written in Ladder Diagram (LD), Soft Comfort will convert it to FBD on upload; the LD aesthetic is lost.
  • The uploaded file is a .lsc (LOGO! Soft Comfort) or .lscz project, not a generic FBD file. It will not open in TIA Portal, STEP 7, or Codesys.

On-Device Programming Limits (FBD Only)

Without any PC connection, the LOGO! 0BA6 supports the following on-device operations using the cursor keys and the OK/ESC buttons:

Action Available on the 0BA6 display? Notes
Edit program online Yes, but only in FBD representation No Ladder view, no STL view, no variable names
Change parameter values of running blocks (timers, counters, thresholds) Yes, after entering Parameter mode via the menu This is the most common field modification path
Add new blocks Yes, via the Program menu; the function block library shown on the display is a subset of the PC library Special functions (analog math, PI controller, pulse relay, etc.) are available; UDFs created in Soft Comfort are not
View program in Ladder Diagram No Hardware limitation; the display cannot render a true LD contact/coil netlist
Upload program to PC Not possible without the LOGO! USB PC cable The display has no file export function

To reach the program-editing menu from the integrated display, hold ESC, then press OK to enter the main menu, navigate to Program → Edit Program, and step through blocks with the up/down keys. Block inputs and outputs are navigated with left/right. New blocks are inserted with the OK key on a free node.

Password Protection — What It Really Does

The 0BA6 supports a 4-character alphanumeric program password. With a password set:

  • Any on-device attempt to Edit Program or to change parameters will prompt for the password. Three failed attempts lock the device for 60 minutes.
  • Soft Comfort Upload → PC operations require the same password.
  • Removing the password on-device is not possible without erasing the user program. The Program → Clear Program action first asks for the password; if the password is forgotten, the only supported recovery is to Clear All, which wipes the program and resets the password.
  • A hard reset does not bypass the password — it simply clears the user program area, after which a new password (or none) is applied on the next save.
Field reality: The user program and the password hash are both in the same EEPROM region. There is no backdoor, master key, or Siemens service tool that can recover a forgotten password. Plan accordingly when commissioning a machine with a LOGO! — record the password in the electrical documentation the day the program is saved.

Memory Card Behavior

Siemens LOGO! memory cards (order code family 6ED1056-…) come in two colors and three sizes. Color is the field-visible indicator of the card's mode:

Color Mode Effect on the controller
Gray Read/Write (removable, hot-insertable in 0BA6+) Holds a backup copy of the program. Can be transferred between identical modules.
Red Write-protected / program-suppress On insertion, the LOGO! is forced to a known program-suppress state. The user program is hidden from the menu and the program cannot be uploaded until the red card is removed.
Yellow / Green (0BA8+) Configuration / firmware copy Used for firmware updates and IP configuration; not relevant to program recovery of 0BA6.

For 6ED1052-1CC00-0BA6 (0BA6), the gray 6ED1056-1BA00-0BA0 (32 KB) or 6ED1056-1CA00-0BA0 (64 KB) cards hold the program backup. To copy the program from the controller to the card:

  1. Power the LOGO! and enter the main menu.
  2. Navigate to Card → LOGO! → Card and select Copy.
  3. Confirm. The controller writes its active program to the card, including the password hash.

The card can then be read by any LOGO! Soft Comfort installation that supports the 0BA6 generation (V7.0 or later). The card is inserted into the PC card reader via a LOGO! card reader, or — on 0BA8 and later — directly via the SD slot of the controller when connected over Ethernet.

A red card blocks this path entirely. The controller will not expose the user program, and Soft Comfort will see the device as program-suppressed. Remove the red card and insert a gray card; the LOGO! will then offer the standard Copy to card menu.

Cable Options for Upload to PC

The 0BA6 has no Ethernet port. The only PC-side upload path is the LOGO! USB PC cable, 6ED1057-1AA01-0BA0. The cable terminates in a 4-pin keyed connector on the LOGO! end (the integrated serial interface on the right side of the module) and a USB-A on the PC end. Driver support is built into Windows 10 and 11; on older Windows versions a virtual COM port driver from the Soft Comfort install media is required.

Cable MLFB Type Works with 0BA6? Works with 0BA8+ Ethernet modules?
6ED1057-1AA00-0BA0 RS-232 (DB-9) No (legacy only) No
6ED1057-1AA01-0BA0 USB Yes Yes (USB port still present on 0BA8)
Standard CAT5 patch Ethernet No (0BA6 has no RJ-45) Yes (0BA8 Standard / 0BA9)

For a 0BA6 controller, the USB cable is non-negotiable. Procure it before any other recovery step. A typical lead time is one to two business days from a Siemens distributor; some industrial supply houses stock the cable as LOGO! USB programming cable.

Software Selection: LOGO! Soft Comfort

LOGO! Soft Comfort is the only engineering tool that can read a 0BA6 program in source form. Versions are cumulative — newer versions can read older projects, but older versions cannot read newer ones:

Soft Comfort version Supports upload from 0BA6? Released Notes
V6.1 Limited (some 0BA6 features missing) 2007 Reference target of the source question
V7.x Yes (full 0BA6 support) 2012 Recommended minimum for 0BA6 projects
V8.x Yes (adds 0BA7/0BA8 support) 2018 Backwards-compatible with 0BA6 files
V8.4 Yes 2022 Last release with broad Windows 7 SP1 support
V9.0 Yes 2024 Adds LOGO! Web Editor and integrated simulation per the Siemens product page

For the task in the source question, a Soft Comfort V7.x or later is preferred over V6.1. V6.1 predates the 0BA6 feature set in some areas (analog scaling block, edge-triggered counters), and the upload operation may produce a project that round-trips incorrectly. The current generation is described on the Siemens LOGO! software product page, which lists the all-in-one download of program and web project introduced in V9.

Licensing note: LOGO! Soft Comfort is free of charge; no license key, no dongle, no online activation. The install can be cloned to a USB drive for field laptops.

Step-by-Step: Upload Program from a 0BA6

  1. Verify the controller part number on the front label matches 6ED1052-1CC00-0BA6 and confirm the 0BA6 platform suffix.
  2. Obtain the LOGO! USB PC cable (6ED1057-1AA01-0BA0). Do not substitute a generic USB-serial adapter; the cable contains a SiLabs CP210x-class bridge and a logic-level shifter that maps the LOGO!'s 5 V serial to USB levels.
  3. Install LOGO! Soft Comfort V7.0 or later. V8.4 is the most conservative choice for a 0BA6-targeted project in 2024–2025 environments. Accept the default virtual COM port driver.
  4. Power the LOGO!. Do not interrupt the field wiring — leave inputs live. The program in the controller is non-volatile and will survive power-down, but the controller must be in Run or Stop mode (not Program-suppress) for the upload to be offered.
  5. Connect the cable: USB end to the engineering PC, keyed end to the LOGO! serial port. Windows will enumerate the device and assign a COM port (typically COM3–COM7 on first connection).
  6. Start LOGO! Soft Comfort. From the menu bar, select Tools → Transfer → Upload from LOGO!… (or the keyboard equivalent, F11 in V8.x). The PC will prompt for a destination folder; the project will be saved as <filename>.lsc (uncompressed) or <filename>.lscz (zipped archive).
  7. If the controller has a password set, Soft Comfort will request it. Enter the four-character password. After three incorrect attempts, the LOGO! enters a 60-minute lockout; restart Soft Comfort to clear the PC-side retry counter only after the lockout has expired.
  8. On success, Soft Comfort opens the uploaded project. The FBD diagram appears in the work area. If the original was authored in Ladder, the FBD view will show the same logic but reorganized as a flat block graph — this is normal, not corruption.
  9. Save the project to a known location. Add a revision note in the comment field. Move a copy to the engineering documentation library.

Verification: Confirm the Upload Is Complete

After upload, perform these checks before trusting the recovered project:

  1. Compare the block count reported by the LOGO! on-device menu (Program → Memory Usage or Info) to the block count displayed in Soft Comfort Tools → Info. A mismatch indicates a partial upload or a password-induced truncation.
  2. Compare the controller's reported program name and password status (if visible) to the Soft Comfort project header.
  3. Run the on-device simulation in Soft Comfort: Tools → Simulation (or F8). The simulator must show the same I/O behavior as the running controller under steady-state conditions. Walk through every input change documented in the machine's sequence-of-operations.
  4. Generate a cross-reference: in Soft Comfort, Tools → Cross Reference lists every block, its inputs, and the connectors that use it. Confirm the count matches the machine's electrical drawing.
  5. If a .lscz archive is required for archival, re-save as a zipped project. The archive contains the source FBD plus the compiled program image and the password hash.

Field Editing Without a Cable — Realistic Use Cases

Some changes can be made on-device without recovering the full program. These are the legitimate field edits and should be the first question asked of any maintenance call:

Required change Best path Limits
Adjust an on-delay or off-delay time On-device parameter change in Parameter mode No password needed if the program was saved with Allow parameter edit flag set
Change a counter preset Same as above Only if the counter block was placed with parameter protection disabled in Soft Comfort
Change an analog threshold Same as above Same flag condition
Add a new branch to the logic Requires PC + cable + Soft Comfort Not possible on-device; the integrated display can only edit the existing block list
Replace a function block with a different one (e.g., PI controller instead of on-delay) Requires PC + cable + Soft Comfort Not possible on-device

When the original commissioning engineer disabled parameter protection, the field technician can make most tuning changes from the display without ever needing a PC. This is the design intent of the on-device edit mode and is the reason LOGO! is popular for small machines.

Troubleshooting Matrix

Symptom Likely cause Resolution
Soft Comfort does not list any COM port USB driver not installed; cable defective Reinstall the CP210x driver from the Soft Comfort install media; try a second cable
Soft Comfort lists the COM port but Upload fails immediately Wrong cable generation (RS-232 cable on 0BA6); incorrect baud setting Use 6ED1057-1AA01-0BA0; in Soft Comfort set the port to the auto-detect default (19200 8 N 1)
Controller reports No Program when PC connects Red memory card inserted; user program was cleared Remove the red card; if the program was cleared, recovery is impossible from the device
Upload returns a partial program with reduced block count Password set and the wrong password was accepted as a partial match (legacy bug on V6.1) Upgrade to V7.x or later; retry with the correct password
Soft Comfort opens the file but the FBD looks messed up Original was authored in Ladder; upload converted to FBD This is not corruption; re-author as FBD or accept the FBD representation
Forgot the password No recovery path Document the loss, clear the program, re-author from the machine's sequence-of-operations and electrical drawing
On-device edit prompts for password but no password was set Residual password from a previous owner; or the program was transferred from a card with a password Clear the program and re-save without a password
Upload succeeds, but the simulation shows different behavior from the running machine I/O wiring changed after the program was saved; or a UDF used in the original is not present in the Soft Comfort version Re-inspect wiring; upgrade Soft Comfort to the version used to author the original program

Cross-Generation Compatibility Notes

If the controller in the field is not a 0BA6 but a 0BA7 or 0BA8 (visually identical, same MLFB family but a different suffix), the recovery path changes in two ways:

  • 0BA8 Standard modules expose a 10/100 Mbit Ethernet port. The USB cable still works, but a standard CAT5 patch cable plus Soft Comfort V8.1+ is the simpler field path. The Ethernet connection does not require a crossover; the LOGO! supports auto-MDI/MDIX.
  • 0BA7 modules add the SD card slot used by the gray memory card. Programs can be copied to a gray SD card on a 0BA7/0BA8 and read into Soft Comfort V8.x without ever opening the controller's wiring compartment — a useful option when the machine is in a wash-down area and the cover cannot be removed.

For 0BA6, the SD card slot does not exist. Only the proprietary LOGO! memory card works, and only via the side slot.

Safety and Documentation Practice

Whenever a LOGO! program is uploaded from a running machine, capture three pieces of evidence at the same time:

  1. The Soft Comfort project file (.lsc or .lscz).
  2. A screenshot of the on-device Memory Usage / Info screen showing block count, program name, and program version.
  3. The electrical drawing of the machine, marked with the I/O addresses used by the program. The 0BA6 supports I1…I8, AI1…AI4, Q1…Q4, AQ1…AQ2 (where present), and the network markers M1…M27 / shift registers S1…S8. The drawing is the only source of truth for the wiring of those addresses, since the uploaded program carries the logic but not the wire list.

Store all three in the same folder, named with the controller's serial number, the date, and the operator's initials. A lost password or a cleared program is then recoverable from the documentation set, not from the controller itself.

FAQ

Can I read a Siemens LOGO! program without the programming cable?

No. The 0BA6 has only the integrated serial port (covered by the small flap on the right side of the module) and a memory card slot. A PC connection requires the LOGO! USB PC cable, order number 6ED1057-1AA01-0BA0. No software path exists that recovers the program from the device without a cable or a gray memory card that the same controller wrote.

Can I view the program on the LOGO! display as a Ladder Diagram?

No. The 0BA6 integrated display can only present the program in FBD form. Even if the original Soft Comfort project was written in Ladder Diagram, the on-device editor will always show FBD blocks. To view the original LD structure, upload the program to a PC running LOGO! Soft Comfort V7.0 or later.

How do I remove a forgotten password from a 6ED1052-1CC00-0BA6?

The only supported method is to clear the user program. There is no master password, no Siemens service tool, and no firmware backdoor for the 0BA6 platform. The password hash and the user program share the same EEPROM region, so clearing the program also clears the password. Re-author the program from the machine's electrical drawing and sequence-of-operations.

What is the difference between the gray and red LOGO! memory cards?

Gray cards hold a backup copy of the user program and allow transfer between identical LOGO! modules. Red cards are write-protected and force the controller into a program-suppress state on insertion, which hides the user program from the menu and from Soft Comfort. To recover a program from a controller that has a red card installed, remove the red card and insert a gray card, then use the on-device Copy-to-Card menu.

Which version of LOGO! Soft Comfort supports a 0BA6 controller?

LOGO! Soft Comfort V7.0 and later fully support the 0BA6 platform, including all special functions and analog blocks. V6.1 (the version named in the original question) is pre-0BA6 for some features and is not recommended for round-tripping modern 0BA6 projects. The current release line, V9, is described on the Siemens LOGO! software product page and supports the 0BA6 generation for upload and editing.

Back to blog