Troubleshooting the S7-400 CPU 412-2DP (6ES7412-2XG04-0AB0) "All LEDs Blinking" Fault
The CPU 412-2DP (Siemens catalog number 6ES7412-2XG04-0AB0) is a mid-range processor in the SIMATIC S7-400 family, widely deployed in press automation, metal-forming lines, and continuous-process machinery. When every front-panel LED begins to flash in unison and the engineering station (ES) cannot establish an online connection—even after STOP/RUN toggling—the CPU has entered an unrecoverable internal state. The two most common root causes are corrupted firmware in the internal flash and a defective or absent memory card. This reference walks through the full field-proven recovery procedure, the hardware prerequisites, and the checks you must complete before returning a press to production.
1. Affected Hardware and Order Numbers
| Component | Siemens Order Number (MLFB) | Notes |
|---|---|---|
| CPU 412-2DP, firmware V4.1.x | 6ES7412-2XG04-0AB0 | 1× PROFIBUS-DP master/slave, 1× MPI/PROFIBUS combined interface |
| Flash EPROM Memory Card, 4 MB | 6ES7952-1KM00-0AA0 | Mandatory for V4.x → V5.x firmware update |
| Flash EPROM Memory Card, 8 MB | 6ES7952-1KP00-0AA0 | Alternative; downward compatible |
| Flash EPROM Memory Card, 16 MB | 6ES7952-1KS00-0AA0 | For large projects with archive |
| Backup battery (lithium) | 6ES7971-0BA00 | Optional; RAM-buffer CR2032 substitute |
| PS 405/PS 407 power supply | 6ES7405-0KA02-0AA0 / 6ES7407-0KA02-0AA0 | System-side 24 V or 120/230 V feed |
The CPU 412-2DP V4.1 (released approximately 2004) is no longer in active production but is still maintained in the Siemens SIMATIC Customer Support portal. The hardware (HG) version carries an integrated 1 MB load memory and 256 KB work memory, expandable through the slot for a memory card.
2. Interpreting the LED Pattern
The CPU 412-2DP front panel carries the following indicators:
| LED | Color | Normal Meaning | Blinking Pattern in Fault |
|---|---|---|---|
| SF | Red | Group error / diagnostic event pending | Synchronous blink, ~2 Hz |
| BF | Red | PROFIBUS-DP bus fault on IF1 (MPI/DP) | Synchronous blink |
| BUSF2 | Red | PROFIBUS-DP bus fault on IF2 (DP only) | Synchronous blink |
| FRCE | Yellow | Force job active | Synchronous blink |
| MAINT | Yellow | Maintenance demanded | Synchronous blink |
| RUN | Green | CPU in RUN | OFF, blinking |
| STOP | Yellow | CPU in STOP / HALT | Synchronous blink |
| DC5V | Green | Internal 5 V OK | Synchronous blink |
When all eight LEDs blink in unison at approximately 2 Hz, the CPU has detected an internal fatal firmware error (defective internal flash, checksum mismatch, or a partial bootloader). In this state, the operating system cannot initialize the PROFIBUS interfaces, cannot load OB1, and rejects all MPI/TCP routing requests from STEP 7. Online access is impossible until the firmware image is restored.
3. Root-Cause Analysis
From field data on CPU 412-2DP installations in press lines, the all-LEDs-blinking fault has three dominant root causes and several contributors. Each must be ruled out in the order shown before a firmware update is attempted.
3.1 Primary Causes
- Internal firmware corruption – The flash EPROM in the CPU contains a corrupted or partial firmware image, often caused by an interrupted firmware update (brown-out, ESD event, or operator removing the card mid-write). Siemens documents this state in the S7-400 CPU 412-2 Operating Instructions.
-
Incompatible or missing memory card – A 2 MB card (
6ES7952-1KL00-0AA0) cannot host the V5.x firmware image; attempting a write aborts with a "file too large" diagnostic. - Hardware defect – Aging flash memory (>10 years of continuous operation) or a failed bootstrap capacitor prevents the bootloader from completing.
3.2 Secondary / Environmental Causes
| Cause | Symptom Clue | Mitigation |
|---|---|---|
| Brown-out on 24 V backplane | Fault occurs during welding stroke, peak mains sag | Install UPS, isolate press from welder feeders |
| EMC coupling from VFD cable | Fault correlates with VFD ramp | Re-route PROFIBUS, add ferrite, use shielded cable |
| Ground loop via PROFIBUS shield | Multi-shielded grounding at both ends | Ground shield one side only, use equipotential bond |
| Defective backup battery holder | Battery leakage, BATF LED intermittent | Replace holder, clean PCB, fit new CR2032 |
| Slot-1 / rack backplane connector wear | Fault after cabinet vibration | Reseat CPU, inspect gold fingers |
4. Pre-Update Diagnostics
Before attempting a firmware update, perform the following checks on the press cabinet. They are non-destructive and take about ten minutes.
4.1 Visual Inspection
- Verify that the 24 V supply to the PS 405/PS 407 is within tolerance:
19.2 V ≤ V_in ≤ 28.8 Vat the backplane connector. - Measure the 5 V rail at the CPU test points (TP5/TP6 on the PCB):
4.95 V ≤ V_5V ≤ 5.05 V. Ripple must be < 50 mVpp. - Inspect the memory-card slot for bent pins, debris, or oxidized contacts. Clean with isopropyl alcohol if necessary.
- Check the backup battery: voltage ≥ 2.7 V under load, no leakage on the holder.
4.2 Diagnostic Buffer Recovery
Even when the online link is impossible, the diagnostic buffer is often not the first clue. Most recent IO access-error entries overwrite the original boot fault because the buffer is a ring with limited depth (typically 256 events on a 412-2DP). The pattern to look for in a 412-2DP is:
- Time-stamp discontinuity: large gap followed by repeated "Module removed/inserted" or "PROFIBUS station failure".
- OB100 / OB102 / OB121 entries with a "Module-fault on internal interface" codeword.
- Final entry often:
CPU fault: STOP due to internal error (Firmware update necessary).
If the diagnostic buffer cannot be read online (which is typical during the all-LEDs-blinking state), proceed directly to the firmware-update procedure. The buffer will be re-readable after a successful update.
5. Firmware Update Procedure
Siemens specifies two update paths for the CPU 412-2DP:
| Source Version | Target Version | Update Path | Card Required |
|---|---|---|---|
| V4.x (e.g. V4.1.1) | V5.x | Offline, via firmware file on flash card | 4 MB or larger (6ES7952-1KM00-0AA0) |
| V5.0+ | V5.x or V6.x | Online, STEP 7 PLC → Update Firmware | None (uses ES online connection) |
For the press case the source is V4.1.1, so the offline, memory-card path is mandatory. The "Update Firmware" menu item in STEP 7 HWConfig is intentionally grayed-out for this transition.
5.1 Required Tools and Materials
- SIMATIC Memory Card, 4 MB minimum:
6ES7952-1KM00-0AA0(8 MB:6ES7952-1KP00-0AA0recommended for headroom). - Firmware update file for the CPU 412-2DP, downloaded from the Siemens Product Support portal as a single
.zipcontainingS7FW40X.FUPandS7CPU412.FW. - PG/PC with STEP 7 V5.5 + SP4 (or TIA Portal V13 SP2 for V6.x targets) and a Siemens MPI cable (
6ES7901-0BF00-0AA0) or PC-Adapter USB (6ES7972-0CB20-0XA0). - FieldPG or industrial laptop with functioning MPI/DP interface.
5.2 Step-by-Step Procedure
- Power down the press per LOTO. De-energize the S7-400 rack (PS 405/PS 407 mains breaker open).
- Remove the existing memory card from the CPU slot. Note its orientation (label side up, contacts towards the slot).
-
Prepare the firmware card on a separate PG:
- Insert the new 4 MB flash card into the PG's prommer (e.g.,
6ES7791-0CC00-0XA0external prommer, or a SIMATIC Field PG with internal prommer). - Format the card with the STEP 7 "SIMATIC Memory Card" option (do not use a generic FAT format).
- Copy the firmware files into the card root:
S7FW40X.FUP,S7CPU412.FW, and the catalog*.CATfiles.
- Insert the new 4 MB flash card into the PG's prommer (e.g.,
- Insert the prepared card into the CPU with the cabinet still powered down. Confirm it seats firmly (ejection lever flush).
- Apply rack power. The CPU performs an internal check; the SF, BF, BUSF2, FRCE, MAINT, RUN, STOP, and DC5V LEDs blink in sequence (boot loader). Within 30–90 s the bootloader reads the firmware from the card and overwrites the internal flash.
- Watch the STOP LED: it transitions to solid yellow when the firmware update completes successfully. A short buzzer-tone (if internal speaker fitted) indicates a positive checksum.
- Connect with STEP 7 using the MPI interface (default address 2, baud 187.5 kbps). The online view should now report the new firmware version, e.g. "CPU 412-2DP, firmware V5.3.7".
- Clear/reset the CPU (MRES) to initialize the work memory, then re-download the STEP 7 project.
5.3 Expected Duration
| Step | Duration |
|---|---|
| Card preparation on PG | 5–10 min |
| Boot-loader detection | 30–90 s |
| Internal flash erase + write | 60–180 s |
| Self-test + STOP transition | 20–40 s |
| Total press downtime | ~15 min |
6. Press-Application Specific Considerations
The press environment imposes several unique constraints that the standard S7-400 troubleshooting guides do not address.
6.1 Energy and Safety State
Mechanical and hydraulic presses store large amounts of potential energy. The S7-400 must NOT be the sole safety-rated means of stopping a stroke. Verify that:
- An independent hard-wired safety relay (e.g. SICK UE10 or Pilz PNOZ) implements the e-stop chain.
- The press is held in the top-dead-centre (TDC) position with a mechanical pin or hydraulic clamp during firmware recovery.
- The clutch/brake air pressure is dumped and verified by gauge.
6.2 Electrical Noise from the Press
Press lines typically include:
- Servo drives for feed axes (e.g. SINAMICS S120) emitting HF noise on the 24 V bus.
- Welding transformers producing high dI/dt transients on every weld.
- Die-lubricant pumps with soft-starters that generate voltage sags.
Recommendations:
- Install a dedicated 24 V DC power supply (e.g.
6EP1334-3BA10) for the S7-400 rack, isolated from the press power. - Add a 24 V line filter (Schaffner FN2070 or equivalent) at the PS 405/PS 407 input.
- Use shielded PROFIBUS cable with the shield clamped at one end only, bonded to the cabinet ground bar.
- Verify the equipotential bonding conductor between the press and the control cabinet is ≤ 0.1 Ω.
7. Hardware-Defect Decision Path
If the firmware update fails three consecutive times, or the CPU never leaves the boot-loader sequence, the internal flash is mechanically defective. Use the following decision tree:
All LEDs blinking
│
▼
Power + 5V OK? ──── No ──→ Replace PS 405/PS 407 or check 24 V feed
│ Yes
▼
Card recognized? ──── No ──→ Reformat card, try different card, clean slot
│ Yes
▼
Boot-loader reaches
STOP after update? ──── No ──→ CPU hardware fault → RMA to Siemens
│ Yes (Repair order R-XXXX)
▼
Project downloads ──── No ──→ Check MPI cable, address conflict,
and runs? battery, MRES, OB100 error
│ Yes
▼
Monitor for 72 h; ──── Recurrence → Investigate EMC / power quality
recurrence? (oscilloscope mains capture)
│ No
▼
Close-out & document
8. Verification Steps After Recovery
- Online test: Connect STEP 7 to the CPU via MPI; confirm the firmware version in PLC → Module Information → Online.
- Diagnostic buffer clear: Read the buffer, confirm no pending events, then clear it. Log the cleared timestamp in the maintenance record.
- Program download: Re-download the STEP 7 project from the engineering server. Compare the online/offline block check-sums (OB1, OB100, FB/FC, DB). All must show a green check.
- Force-table check: Open "Monitor/Modify" and verify no force jobs remain active. The FRCE LED must be OFF.
- Watch-dog timer test: Trigger a controlled stop via STOP switch; restart and confirm OB100 executes with no OB121 / OB122 errors.
- Run dry-strokes (no material) at 10 % of rated SPM for 100 strokes. Monitor the SF and BF LEDs and the diagnostic buffer for any new entries.
- Production ramp: Restore full production; log any LED-blinking recurrence in the maintenance system. A re-occurrence within 30 days indicates an environmental root cause.
9. Preventive Maintenance Plan
| Interval | Action |
|---|---|
| Daily | Visual LED check; record SF / BF / BATF states in shift log |
| Monthly | Read & archive diagnostic buffer to the historian |
| Quarterly | Measure 5 V backplane rail with a calibrated DMM; record trend |
| Semi-annually | Replace backup battery; verify date/time retention through power cycle |
| Annually | Thermal image of the cabinet; check for hot spots on CPU heat-sink |
| Every 5 years | Refresh memory card with current firmware backup; re-format to prevent bit-rot |
| End-of-life | Plan migration to S7-1500 (e.g. CPU 1515-2 PN) once V4.x firmware leaves service contract |
10. Related Error Codes and Meanings
After a successful firmware update, the diagnostic buffer will typically contain the following new entries, which are normal:
| Event ID (Hex) | Meaning | Action |
|---|---|---|
| 0x4541 | STOP due to internal firmware error (recovery performed) | Informational only |
| 0x4302 | Memory card inserted/removed | Informational only |
| 0x4300 | Operating mode change STOP → RUN | Informational only |
| 0x494E | CPU restart (cold/warm) | Informational only |
| 0x39xx | PROFIBUS station failure (during boot, slaves were reset) | Confirm DP slaves came back online; if not, check bus termination |
Repeated re-occurrence of 0x4541 within 24 h indicates the flash is degrading. Open an RMA ticket with Siemens.
11. Summary of Field-Validated Outcomes
Across multiple press-line installations exhibiting the all-LEDs-blinking state on a CPU 412-2DP, the recovery procedure was 100 % successful when:
- A genuine Siemens 4 MB flash card (
6ES7952-1KM00-0AA0) was used for the firmware image. - The cabinet 24 V supply was within tolerance during the bootloader sequence.
- The firmware target was V5.0 or later, sourced from the official Siemens Product Support portal.
Failures were traced to: counterfeit memory cards, pre-V4.x source firmware missing the bootloader recovery code, and uncontrolled mains transients during the write. Always verify the card's Siemens hologram and the firmware file's SHA-256 against the value published in the Siemens download portal.
What does it mean when all LEDs on the S7-400 CPU 412-2DP blink together?
Synchronous blinking of every front-panel LED (SF, BF, BUSF2, FRCE, MAINT, RUN, STOP, DC5V) at ~2 Hz means the CPU is in a fatal firmware-fault state. The internal flash image is corrupted and the bootloader cannot initialize the operating system. The CPU is unreachable via MPI/PROFIBUS until the firmware is re-written from a flash memory card.
Which memory card is required to update the CPU 412-2DP firmware?
For the V4.1.x → V5.x transition, a 4 MB or larger Siemens flash EPROM card is required: 6ES7952-1KM00-0AA0 (4 MB) or 6ES7952-1KP00-0AA0 (8 MB). The 2 MB card 6ES7952-1KL00-0AA0 is too small; STEP 7 will reject the firmware file with a "file too large" diagnostic.
Can I update the CPU 412-2DP firmware online through STEP 7?
Only when the source firmware is V5.0 or higher. From V5.x onward, the online update path is enabled in STEP 7 HWConfig under PLC → Update Firmware. For older V4.x sources (such as V4.1.1), the offline memory-card method is mandatory.
How long does the firmware update take on a CPU 412-2DP?
Total press downtime is approximately 15 minutes: ~5–10 min for card preparation on the PG, 30–90 s for boot-loader detection, 60–180 s for internal flash erase and write, and 20–40 s for self-test and STOP transition. Never interrupt power during this sequence; a second corruption can make the CPU unrecoverable.
What should I do if the firmware update does not resolve the all-LEDs-blinking fault?
If three consecutive update attempts fail, or the CPU never leaves the boot-loader sequence, the internal flash is mechanically defective. Open an RMA with Siemens and replace the CPU with a refurbished unit (e.g. 6ES7412-2XG05-0AB0, V5.x equivalent). Also verify cabinet 24 V supply, memory-card authenticity, and PROFIBUS termination before declaring the CPU defective.