1. Symptom Definition and Operational Context
The SIMATIC S5-948 CPU (used in SIMATIC S5-135U and SIMATIC S5-155U PLC systems) can enter a documented abnormal state immediately after a user loads a backup program onto the flash memory card and performs an overall reset. In this state, neither the green RUN LED nor the red STOP LED on the CPU front panel illuminates; the yellow BASP LED remains continuously lit. The specific pattern of "RUN blinks once after overall reset, then all LEDs off except BASP" is a precise diagnostic signature that points to a startup-time fault that prevents the CPU from completing the transition from STOP to RUN.
The symptom is recoverable in the vast majority of cases without replacing the CPU, because the underlying causes are split between three functional layers: (a) startup organization block execution, (b) know-how protection or authorization binding, and (c) power-supply load-voltage monitoring at the rack. Each layer has a deterministic test path on the bench or in the cabinet. This article documents all three layers with diagnostic procedures, parameter tables, and a step-by-step recovery sequence that does not require sending the card back to the machine vendor.
RUN and STOP. This rules out a hard CPU failure on the bench and confines the search to program-related issues on the loaded card, the memory card itself, and the support environment (load voltage, backplane battery, mode selector).2. Hardware and Software Identification
The CPU 948 family was produced in several hardware revisions, and the exact order number determines the supported memory card type, the firmware behaviors at startup, and the applicable STEP 5 package version. The order numbers listed below are the field-relevant releases for flash card support:
| Order Number (MLFB) | Designation | Work Memory | Load Memory | Flash Card Slot | Minimum STEP 5 |
|---|---|---|---|---|---|
| 6ES5 948-3UA11 | CPU 948 | 64 KB | 32 KB | No (EPROM only) | STEP 5 ≥ 6.x |
| 6ES5 948-3UA21 | CPU 948 | 128 KB | 64 KB | Yes (single) | STEP 5 ≥ 7.0 |
| 6ES5 948-3UA22 | CPU 948 | 128 KB | 64 KB | Yes (single) | STEP 5 ≥ 7.0 |
| 6ES5 948-3UB11 | CPU 948B | 256 KB | 128 KB | Yes (single) | STEP 5 ≥ 7.0 |
| 6ES5 948-3UB21 | CPU 948B | 512 KB | 256 KB | Yes (dual) | STEP 5 ≥ 7.2 |
The system manuals for the S5-135U and S5-155U racks describe the rack layout, slot addressing, and CPU slot restrictions. The CPU must be placed in slot 2 of the central rack (CR) or expansion rack (ER) with the IM 300 / IM 301 interface modules in adjacent slots; an S5-948 will not power up correctly if installed in an S5-115U rack that does not support the wider backplane. Verify the rack family before troubleshooting by reading the rack nameplate; the rack designation is printed on the lower-right portion of the chassis. Mixing a CPU 948 with an S5-100U or S5-115U power supply module produces a BASP-stuck pattern identical to the one observed, because the PS 951 / PS 952 24 V load-voltage monitoring path is missing on the smaller supply.
The Programming Device (PG) must be loaded with STEP 5 in a release that supports online diagnostics against the firmware version installed on the target CPU. Use the Siemens Industry Online Support portal to cross-check the firmware compatibility matrix between the PG software package (BASIC, COMFORT, or PRO) and the CPU 948 firmware before attaching the PG. STEP 5 versions older than 6.5 cannot decode the firmware identifier on a CPU 948B and will reject the online connection.
3. BASP LED Function, State Machine, and Timing
BASP stands for Befehls-Ausgabe-Sperre (German: command output inhibit). Internally, BASP is a single bit in the system program that, when set, forces every digital output of every I/O module to the safe state (24 V off / 0 V on sinking modules, 0 V off on sourcing modules). The BASP LED on the CPU front panel mirrors this internal bit and is therefore a real-time indicator of output-inhibit state, not of CPU run state.
| Trigger Source | Set Condition | Clear Condition | CPU State at the Time |
|---|---|---|---|
| Mode selector STOP | Switch moved to STOP | Mode selector RUN and startup complete | STOP |
| System startup sequence | Entry to OB 21 / OB 22 | OB 21 / OB 22 returns and OB 1 begins | STARTUP → RUN |
| PG command "BASPL" on | PG issues force-BASP via online function | PG issues "BASPL" off | STOP or RUN |
| Load voltage monitoring (PS 951 / PS 952) | 24 V load supply missing at terminal | 24 V load supply restored | STOP, STARTUP, or RUN |
| User program (OB 1) | User sets BASP via system FB (SFB 0) | User clears BASP via system FB | RUN |
| Battery low or memory error | Battery below threshold or parity error | Successful overall reset | STOP or STARTUP |
The relevant timing for the reported symptom is the startup window: when the CPU powers up or is reset and a valid program is present, the system program forces BASP on at the start of OB 21 (restart) or OB 22 (cold restart), executes the user-written startup code, and only clears BASP at the end of the startup OB if execution completes without error. If OB 21 / OB 22 does not complete (infinite loop, illegal instruction, indirect addressing fault, or password-protected block that cannot be decrypted), the CPU stays in STARTUP state with BASP set; the front panel shows neither RUN (startup did not finish) nor STOP (the CPU is still in startup), but only BASP.
This is precisely the pattern reported: RUN blinks once (the system initially strobes RUN as it enters startup), then all LEDs go off except BASP, because the system has neither committed to RUN (no successful startup) nor fallen back to STOP (startup is still pending). A timing diagram for the relevant signals is shown below:
RUN with BASP on if the load voltage monitoring input is open. Conversely, a CPU can be in STOP with BASP off (after the mode selector is moved to STOP and BASP is cleared by the system). Always read BASP in conjunction with RUN and STOP.4. Root Cause Matrix
| ID | Cause | Probability | LED Pattern | Resolution Path |
|---|---|---|---|---|
| C1 | Load voltage (24 V) missing at PS 951 / PS 952 monitor input | High | RUN blinks once → all off except BASP | Restore 24 V to monitor terminal |
| C2 | Know-how-protected block referenced in OB 21 / OB 22 | High (vendor-protected machines) | RUN blinks once → all off except BASP | Obtain password or unprotect on PG |
| C3 | Indirect addressing fault in OB 21 / OB 22 (corrupted DB pointer) | Medium | RUN blinks once → all off except BASP | Reload program from known-good source |
| C4 | Memory card type mismatch (wrong card type plugged into flash slot) | Medium | RUN blinks once → all off except BASP | Reprogram card on PG with correct type |
| C5 | Infinite loop in OB 21 / OB 22 (vendor protection by design) | Medium | RUN blinks once → all off except BASP | Patch startup OB or replace with known-good program |
| C6 | Battery exhausted in CPU (volatile markers lost) | Low | Battery LED + BASP | Replace battery, overall reset, reload |
| C7 | Memory card physically faulty (corrupt sectors) | Low | RUN blinks once → all off except BASP | Replace card with same order number |
| C8 | CPU hardware fault (backplane, firmware, or component) | Very low | Any pattern, persistent | Swap CPU with spare of same MLFB |
Causes C1, C2, C3, C5, and C7 explain the reported symptom exactly. C6 and C8 produce additional LED indications that the source did not mention; they are included as exhaust-the-possibilities branches so the troubleshooting path remains complete.
5. Diagnostic Procedure: Pre-Power Checks
- Verify rack identity. Read the rack nameplate. Confirm that the chassis is a SIMATIC S5-135U or S5-155U. The CPU 948 will not work in any S5-115U variant. If the rack is correct, continue to step 2.
-
Verify power supply module. Identify the PS module (typically a 6ES5 951-... or 6ES5 952-...). The 951 / 952 modules provide a load voltage monitoring input on the front terminal block labeled
1L/1M, orSUW/SUW+depending on revision. This input must see 24 V DC referenced to chassis ground for the system to release BASP at the end of startup. - Measure load voltage. With the system powered, place a DMM on the load voltage monitoring terminals. Expect 22 V to 30 V DC. A reading below 18 V or above 32 V indicates an undersized or shorted load supply. Record the value for the maintenance log.
- Verify CPU battery. Open the battery compartment on the CPU 948 and inspect the lithium battery (typically a 3.6 V primary cell, AA form factor; Siemens order number 6ES5 980-0MA11). Measure the open-circuit voltage with the battery disconnected for 5 seconds. Anything below 3.0 V indicates a battery that has leaked or lost capacity; the RAM-resident markers (restart bits, retentive flags, retentive timers/counters) are no longer reliable, and an overall reset is mandatory after replacement.
-
Inspect the mode selector. Confirm the selector is in the
RUNorRUN-Pposition. If the selector is inSTOP, the system stays inSTOPby design; BASP is also set because the CPU is not allowed to drive outputs while the operator can manually intervene. - Inspect the flash memory card. Remove the card from the CPU slot. Examine the edge connector for oxidation or contamination. Reseat firmly. Note the card label: valid types for the CPU 948 are 6ES5 374-2x (32 KB), 6ES5 374-2x (64 KB), or 6ES5 374-2x (128 KB) flash EPROM cards. An EPROM submodule that has not been erased (the sticker window must be covered after erasure) will produce a checksum error during load and lead to BASP-stuck behavior.
- Verify card orientation. The CPU 948 slot is keyed to prevent reverse insertion, but the key is mechanical and can be defeated by forcing. Verify the card label faces the same direction as the CPU's label, and the arrow on the card aligns with the slot arrow.
6. Startup Organization Block (OB) Analysis and Decompilation
The CPU 948 executes two distinct startup organization blocks:
- OB 21 — Restart (warm restart). Triggered after power recovery with battery-backed RAM intact, or after an overall reset with retentive data preserved. OB 21 expects the system to be in a defined state (all outputs cleared, BASP set).
- OB 22 — Cold restart. Triggered after power-up with a missing or corrupted battery, or after an overall reset with the cold-restart selector position selected. OB 22 also clears all non-retentive flags, timers, and counters.
The system forces BASP on at the entry of OB 21 or OB 22 and clears BASP only after the OB returns and the cyclic OB 1 begins. Any error inside the startup OB keeps the system in STARTUP state forever and leaves BASP set. Typical fault patterns inside the startup OBs are:
-
Indirect addressing fault. The OB performs a
DO DW[AR1]style loop that walks a data block whose pointer was initialized to 0 (because a DB was lost in the overall reset). The system raisesOB 121(programming error); ifOB 121is not present in the loaded program, the CPU transitions toSTOP; ifOB 121is present and the manufacturer coded it to ignore the error, the startup OB hangs. -
Infinite loop. The manufacturer intentionally coded a
L KB 0 / T FW 0 / JU OB1style loop or a tightSU0loop to bind the startup to the original card as an anti-piracy measure. -
Password-protected block call. A
JU FB 200in the startup OB references a function block protected with the STEP 5 know-how attribute. The PG can display the call but cannot display the block body. Without the password, the CPU may fail to load the block at startup, depending on the firmware version.
To analyze the OBs without executing them, connect the PG to the CPU 948 via the PG cable (MPI or serial, depending on the CPU interface), go online, and use the STEP 5 menu PLC > Display > OB 21 and PLC > Display > OB 22. The decompiled STL listing shows the actual instructions. Look for: indirect addressing (any DO instruction), unconditional jumps (JU) back into the same OB, calls to FBs that show a question mark or hash in the body (encrypted), and CALL statements to DBs that are not loaded. Each one is a candidate root cause.
If a vendor protection is suspected, the only legitimate remediation is to request the original program with password from the machine manufacturer. Reverse-engineering a vendor-locked startup OB to bypass the protection may violate the End User License Agreement and local law; this article documents the diagnostic only and does not provide bypass procedures.
7. Know-How Protection and Password Handling
STEP 5 supports a per-block know-how protection that hides the body of an FB, FX, or DB behind a password. The protection is set with the STEP 5 editor: open the block, choose File > Block > Properties > Know-how protection, enter the password, save. From that point on, every PG that tries to display the block receives a placeholder body with the message "Block is protected."
On the CPU 948, a protected block does execute at runtime if the password matches a password stored in the CPU's protected area; otherwise the block fails to load at startup. The system cannot distinguish at startup between "block encrypted but password known" and "block encrypted but password unknown," so the symptom is the same in both cases. The differences are:
- If you possess the password, connect the PG, go online, choose PLC > Password > Enter, type the password, then display OB 21 / OB 22. The blocks will now decompile to source STL and you can inspect the startup logic.
8. Power Supply Module and Load Voltage Monitoring
The PS 951 (5 V / 24 V) and PS 952 (15 V / 24 V / 5 V) power supply modules for the S5-135U and S5-155U racks include a load voltage monitoring input. The terminal block on the front of the module carries pins that route the external 24 V load supply into the system. When the 24 V is present, the input is active and BASP is allowed to clear at the end of startup. When the 24 V is missing, the input is open and BASP is held set by the system, regardless of the CPU run state.
| Module | Order Number | Load Voltage Terminals | Nominal | Threshold (BASP cleared) | Threshold (BASP held) |
|---|---|---|---|---|---|
| PS 951 | 6ES5 951-7ND21 | 1L / 1M | 24 V DC | ≥ 19.2 V | ≤ 18.0 V |
| PS 951 | 6ES5 951-7LD21 | 1L / 1M | 24 V DC | ≥ 19.2 V | ≤ 18.0 V |
| PS 952 | 6ES5 952-1AH00 | 1L+ / 1M | 24 V DC | ≥ 19.2 V | ≤ 18.0 V |
| PS 952 | 6ES5 952-1AK00 | 1L+ / 1M | 24 V DC | ≥ 19.2 V | ≤ 18.0 V |
The threshold has a 1.2 V hysteresis to prevent oscillation when the load supply is marginal. A machine that has recently been wired or rewired may have the load voltage monitoring input disconnected or routed to a separate breaker that is now off. Always check the breaker feeding the 24 V load supply before suspecting software. With the load voltage missing, the CPU 948 enters startup, attempts to run OB 21 / OB 22, finishes (or fails to finish) without errors, but cannot clear BASP because the system-level interlock from the power supply module is active. The LED pattern in this case is BASP on with RUN and STOP also on their normal states; if the CPU also fails OB 21 / OB 22, the BASP-only pattern observed here is the combined result of two faults (load voltage missing and startup fault).
9. Memory Card Programming Procedure
The flash memory card for the CPU 948 must be programmed on a PG (not in the CPU slot) using the STEP 5 file system. The procedure is:
- Insert the card into the PG's memory card slot or external card writer (the PG 720, PG 740, PG 760, and Field PG all support the S5 flash card adapter).
-
Open STEP 5 and select the project that contains the S5 program. If the program came as a backup file (typically with extension
.S5Dor a set of cross-reference files plus.STLsources), use File > Open Project and point to the directory. -
Compile the program with Project > Compile. The compile step generates the loadable blocks (OB, FB, FC, DB, PB, SB, FX) in the
S5DATdirectory. - Select the card target with PLC > Memory Card > Flash EPROM. STEP 5 prompts for the card size; choose the size that matches the physical card (32 KB, 64 KB, or 128 KB).
- Erase the card with PLC > Memory Card > Erase. The erase time is 10 to 60 seconds depending on card size; the PG shows a progress bar.
- Program the card with PLC > Memory Card > Program. The PG writes each block sequentially, verifies each block, and reports a final checksum. A failed write leaves the card in an indeterminate state; repeat the erase and program cycle.
- Verify the card with PLC > Memory Card > Compare. The compare reads the card back and verifies every block against the source.
- Insert the card into the CPU 948's flash slot with the system powered off. Power on. The CPU reads the card, performs the system-side checksum, and either accepts the program or rejects it with a fault LED.
10. Step-by-Step Recovery Sequence
Apply the following sequence in order. Each step is independent; if the symptom is resolved at any step, stop and document the root cause before proceeding.
- Power down the rack. Open the main breaker. Wait 30 seconds for the PS module capacitors to discharge.
- Remove the flash card. Note orientation; the CPU 948 slot is keyed to prevent reverse insertion, but verify alignment before reinserting.
- Power up with no card. Close the breaker. Observe LEDs. If RUN and STOP behave normally (RUN can be forced by mode selector), the CPU is healthy. Continue to step 4.
- Restore the load voltage monitoring input. With a DMM, verify 24 V DC on the PS module monitor terminals. Restore any tripped breaker. If the symptom is now BASP-only (RUN and STOP both on, BASP also on), the original symptom had a power-supply contribution; resolve the load-voltage path first.
- Replace the CPU battery. Install a fresh 3.6 V lithium cell (order number 6ES5 980-0MA11 or equivalent). Power down, swap, power up. The CPU will perform a cold restart; this is expected.
- Insert the flash card and observe. Power down, insert card, power up. If the symptom persists (RUN blinks once, then BASP-only), proceed to step 7.
- Connect the PG and go online. Use the PG cable to the CPU's PG port. Start STEP 5, PLC > Display > OB 21 and OB 22. Read the startup OB source. Look for indirect addressing or unconditional loops. If found, the original program is the root cause.
- Strip know-how protection (if authorized). If you are the machine owner and have the password, go online and remove the know-how attribute from the startup OBs. Re-compile, re-program the card.
-
Substitute a no-op startup OB (if authorized). Replace OB 21 and OB 22 with empty blocks containing only
BE. Re-compile, re-program the card. This forces the system to skip the user startup logic; BASP will clear normally. Use only when the protected logic is not required for safety. - Swap the flash card. If step 9 still shows BASP-only, the card itself may be marginal. Try a known-good card of the same order number and size. Power down, swap, power up.
- Swap the CPU with a spare. If steps 1 to 11 do not resolve the symptom, install a spare CPU 948 of the same order number. If the spare runs the same card cleanly, the original CPU has a hardware fault and must be replaced.
11. Verification and Re-Commissioning
-
Force RUN. Move the mode selector to
RUN. Confirm that the greenRUNLED is on steady,STOPis off, andBASPis off. - Check outputs. Use a voltmeter on a sample output terminal (e.g., Q 0.0 on the first DO module). The output should reflect the program logic. If outputs remain at 0 V with BASP off, the issue is program-level, not system-level.
- Verify retentive data. Trigger a power-cycle and confirm that retentive flags, timers, and counters hold their values. If not, the battery swap in step 5 was not performed or the new battery was not seated correctly.
- Check Profibus nodes. The CPU 948 supports Profibus-DP via the CP 5431 module. Use the Profibus diagnostic tool to confirm that all configured slaves are visible and exchanging data. If a slave was lost during the troubleshooting, the system will raise a Profibus diagnostic interrupt that may keep BASP set in some machine configurations.
- Document the program checksum. On the PG, choose PLC > Display > System Information > Checksum. Record the program checksum in the maintenance log so future reloads can be verified against the original.
- Save the project to PG disk. Use File > Save Project on the PG. Store the archive on a network share and on the machine documentation. This ensures that the next BASP event has a known-good source to reload from.
12. Frequently Asked Questions
What does BASP on with RUN and STOP off mean on an S5-948?
The CPU is stuck in the startup window: it has not completed OB 21 (restart) or OB 22 (cold restart), so neither RUN nor STOP is set, but BASP is held on because the system has not reached the end of startup to clear it. Common causes are an OB that contains an indirect addressing fault, an infinite loop, or a reference to a know-how-protected block whose password is not available. Verify load voltage on the PS 951 / PS 952 module first, then analyze OB 21 / OB 22 online with the PG.
Can the S5-948 CPU be defective when BASP is on with no program loaded?
Almost never. When no card is inserted and no program is present, the CPU transitions between RUN and STOP by design. A persistent BASP-only state in this configuration indicates that the load voltage monitoring input on the PS 951 / PS 952 module is not receiving 24 V DC, not a CPU fault. Restore the 24 V at the monitor terminal and BASP will clear on the next startup.
How do I remove know-how protection on a STEP 5 block?
Open the block in the STEP 5 editor on a PG that has the password, choose File > Block > Properties > Know-how protection, clear the password, and save. Reload the block to the PLC or re-program the flash card. If the password is unknown, request a clean unprotect from the original machine manufacturer; bypassing a know-how protection without authorization may violate the End User License Agreement and local law.
Why does the flash memory card need to be programmed on the PG and not in the CPU?
The CPU 948 cannot write to its own flash card; it can only read from it. Programming a flash EPROM requires an external voltage and timing that the CPU slot does not provide. Use the PG's card slot or an external Siemens-licensed programmer, erase the card, write the load image, verify, then insert the card into the CPU slot with the system powered off.
What is the difference between OB 21 and OB 22 on the S5-948?
OB 21 is the warm restart (battery-backed RAM intact, retentive data preserved); OB 22 is the cold restart (battery missing or cold-restart selector position, all non-retentive data cleared). The system invokes one or the other based on the battery state and the operator's restart selection. Both OBs start with BASP set, and both must complete without error for BASP to clear and RUN to be set.